๐Ÿ” CVE Alert

CVE-2023-0330

MEDIUM 5.3

Qemu: lsi53c895a: dma reentrancy issue leads to stack overflow

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

CWE CWE-121
Published Mar 6, 2023
Last Updated Aug 2, 2024
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new medium vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2023-0330 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2160151 lists.debian.org: https://lists.debian.org/debian-lts-announce/2023/10/msg00006.html lists.nongnu.org: https://lists.nongnu.org/archive/html/qemu-devel/2023-01/msg03411.html

Credits

Red Hat would like to thank Zheyu Ma for reporting this issue.