QEMU: NVMe: out-of-bounds memory access in nvme_sriov_pre_write_ctrl()
Published Feb 19, 2024
6.0
MEDIUMCVSS 3.1
EPSS 0.29%
Description
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm-ma
Not affected
Red Hat Enterprise Linux 8
virt:rhel/qemu-kvm
Not affected
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:av/qemu-kvm
Not affected
Red Hat Enterprise Linux 9
qemu-kvm
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-ma | Not affected | n/a |
| Red Hat Enterprise Linux 8 | virt:rhel/qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 9 | qemu-kvm | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The affected code path can only be reached if dev->exp.sriov_cap is set. For example, if QEMU is explicitly launched with the hw/nvme SR-IOV emulation enabled (parameter `sriov_max_vfs` is set). The emulation is exclusively used to emulate NVMe devices with SR-IOV capabilities for host software development purposes. Thus, the security impact of this CVE is Low. The `qemu-kvm` versions, as shipped with Red Hat Enterprise Linux and RHEL Advanced Virtualization, are not affected by this flaw as they did not include support for NVMe emulation.
References (8)
- https://access.redhat.com/security/cve/CVE-2024-26328 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2264896 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-23597 Advisory
- https://lore.kernel.org/all/20240213055345-mutt-send-email-mst%40kernel.org/ Broken Link
- https://lore.kernel.org/all/20240218-reuse-v5-1-e4fc1c19b5a9@daynix.com/
- https://nvd.nist.gov/vuln/detail/CVE-2024-26328
- https://security.netapp.com/advisory/ntap-20240419-0010/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-26328
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data