A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.
2023-08-03T15:15:29.960
2024-11-21T08:16:38.297
Modified
CVSSv3.1: 6.0 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qemu | qemu | < 8.1.0 | Yes |
Application | qemu | qemu | 8.1.0 | Yes |
Application | qemu | qemu | 8.1.0 | Yes |
Application | qemu | qemu | 8.1.0 | Yes |
Operating System | fedoraproject | fedora | 38 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |