Back

MEDIUM

QEMU: NVMe: out-of-bounds memory access in nvme_sriov_pre_write_ctrl()

Published Feb 19, 2024

Description

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.

Affected products

Remediation

Red Hat statement

The affected code path can only be reached if dev->exp.sriov_cap is set. For example, if QEMU is explicitly launched with the hw/nvme SR-IOV emulation enabled (parameter `sriov_max_vfs` is set). The emulation is exclusively used to emulate NVMe devices with SR-IOV capabilities for host software development purposes. Thus, the security impact of this CVE is Low. The `qemu-kvm` versions, as shipped with Red Hat Enterprise Linux and RHEL Advanced Virtualization, are not affected by this flaw as they did not include support for NVMe emulation.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Feb 19, 2024
Updated Nov 6, 2024
Reserved Feb 19, 2024

CISA Vulnrichment

Updated Feb 20, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Feb 19, 2024
Bugzilla 2264896

ENISA EUVD

Assigner mitre
Published Feb 19, 2024
Updated Nov 6, 2024

GitHub

No data