Back

MEDIUM

Qemu-kvm: virtio-net: queue index out-of-bounds access in software rss

Published Jul 5, 2024

Description

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host.

Affected products

Remediation

Vendor solution

A viable mitigation for this vulnerability is to disable RSS on the nic/virtio driver. This can be performed either with the following qemu-kvm command "-device virtio-net-pci,rss=off", or, alternatively, by directly modifying the KVM XML file to disable RSS using a standard configuration tool (ex. libvirt).

Red Hat statement

This flaw has been rated as Moderate because it can only be exploited by privileged users within the guest.

Red Hat mitigation

A viable mitigation for this vulnerability is to disable RSS on the nic/virtio driver. This can be performed either with the following qemu-kvm command "-device virtio-net-pci,rss=off", or, alternatively, by directly modifying the KVM XML file to disable RSS using a standard configuration tool (ex. libvirt).

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 5, 2024
Updated Nov 8, 2025
Reserved Jul 4, 2024
CISA Vulnrichment
Updated Jul 13, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 4, 2024
ENISA EUVD
Assigner redhat
Published Jul 5, 2024
Updated Nov 8, 2025
Exploited since n/a
EUVD-2024-47589