Qemu: vnc: infinite loop in inflate_buffer() leads to denial of service
Published Sep 13, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.89%
Description
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remote authenticated client who is able to send a clipboard to the VNC server to trigger a denial of service.
Affected products
No data.
Configuration 2
- 8.0
- 9.0
Configuration 3
- 38
No data.
Red Hat Enterprise Linux 8
virt-devel:rhel-8100020240314161907.e155f54d
Fixed · RHSA-2024:2962
Red Hat Enterprise Linux 8
virt:rhel-8100020240314161907.e155f54d
Fixed · RHSA-2024:2962
Red Hat Enterprise Linux 9
qemu-kvm-17:8.2.0-11.el9_4
Fixed · RHSA-2024:2135
Red Hat Enterprise Linux 6
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm-ma
Not affected
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:av/qemu-kvm
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | virt-devel:rhel-8100020240314161907.e155f54d | Fixed | RHSA-2024:2962 |
| Red Hat Enterprise Linux 8 | virt:rhel-8100020240314161907.e155f54d | Fixed | RHSA-2024:2962 |
| Red Hat Enterprise Linux 9 | qemu-kvm-17:8.2.0-11.el9_4 | Fixed | RHSA-2024:2135 |
| Red Hat Enterprise Linux 6 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-ma | Not affected | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/qemu-kvm | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The `qemu-kvm` versions as shipped with Red Hat Enterprise Linux 6, 7, and RHEL Advanced Virtualization are not affected by this flaw as they did not include VNC clipboard support (upstream commit 0bf41cab).
References (7)
- https://access.redhat.com/errata/RHSA-2024:2135 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2962 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-3255 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2218486 issue-trackingx_refsource_REDHATIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-3255
- https://security.netapp.com/advisory/ntap-20231020-0008/
- https://www.cve.org/CVERecord?id=CVE-2023-3255
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:2135 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:2962 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2023-3255 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2218486 | issue-trackingx_refsource_REDHATIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-3255 | ||
| https://security.netapp.com/advisory/ntap-20231020-0008/ | ||
| https://www.cve.org/CVERecord?id=CVE-2023-3255 |
Change history (0)
No recorded changes yet.