Qemu-kvm: virtio-net: queue index out-of-bounds access in software rss
Published Jul 5, 2024
6.8
MEDIUMCVSS 3.1
EPSS 0.66%
Description
A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 Advanced Virtualization | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
Configuration 2
- 8.0
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 10
qemu-kvm
Will not fix
Red Hat Enterprise Linux 6
qemu-kvm
Out of support scope
Red Hat Enterprise Linux 7
qemu-kvm
Out of support scope
Red Hat Enterprise Linux 7
qemu-kvm-ma
Out of support scope
Red Hat Enterprise Linux 8
virt:rhel/qemu-kvm
Will not fix
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:av/qemu-kvm
Will not fix
Red Hat Enterprise Linux 9
qemu-kvm
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | qemu-kvm | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | qemu-kvm | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-ma | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | virt:rhel/qemu-kvm | Will not fix | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/qemu-kvm | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | qemu-kvm | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
A viable mitigation for this vulnerability is to disable RSS on the nic/virtio driver. This can be performed either with the following qemu-kvm command "-device virtio-net-pci,rss=off", or, alternatively, by directly modifying the KVM XML file to disable RSS using a standard configuration tool (ex. libvirt).
Red Hat statement
This flaw has been rated as Moderate because it can only be exploited by privileged users within the guest.
Red Hat mitigation
A viable mitigation for this vulnerability is to disable RSS on the nic/virtio driver. This can be performed either with the following qemu-kvm command "-device virtio-net-pci,rss=off", or, alternatively, by directly modifying the KVM XML file to disable RSS using a standard configuration tool (ex. libvirt).
References (6)
- https://access.redhat.com/security/cve/CVE-2024-6505 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2295760 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47589 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6505
- https://security.netapp.com/advisory/ntap-20240816-0006/
- https://www.cve.org/CVERecord?id=CVE-2024-6505
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-6505 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2295760 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47589 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-6505 | ||
| https://security.netapp.com/advisory/ntap-20240816-0006/ | ||
| https://www.cve.org/CVERecord?id=CVE-2024-6505 |
Change history (0)
No recorded changes yet.