Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-3447


A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.


Published

2024-11-14T12:15:17.743

Last Modified

2025-11-03T20:16:26.963

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.0 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-122

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qemu qemu < 7.2.11 Yes
Application qemu qemu < 8.2.3 Yes
Application qemu qemu 9.0.0 Yes
Application qemu qemu 9.0.0 Yes
Application qemu qemu 9.0.0 Yes
Application qemu qemu 9.0.0 Yes
Operating System netapp hci_compute_node - Yes

References