A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a huge number of page tables to be used as a ring of descriptors for CQ and async events, potentially leading to an out-of-bounds read and crash of QEMU.
2023-03-23T20:15:14.497
2025-11-03T20:15:59.780
Modified
CVSSv3.1: 6.0 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | qemu | qemu | ≤ 7.2.0 | Yes |
| Operating System | fedoraproject | fedora | 37 | Yes |