CVE-2023-6693

CVSS V2 None CVSS V3 None
Description
A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables allocated on the stack. Specifically, the `out_sg` variable could be used to read a part of process memory and send it to the wire, causing an information leak.
Overview
  • CVE ID
  • CVE-2023-6693
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-01-02T09:15:08.280Z
  • Last Modified Date
  • 2024-05-29T23:07:42.729Z
History
Created Old Value New Value Data Type Notes
2024-06-25 06:11:24 Added to TrackCVE