A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.
2024-04-10T15:16:05.097
2025-05-06T09:15:17.727
Modified
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qemu | qemu | < 8.2.3 | Yes |
Application | qemu | qemu | 9.0.0 | Yes |
Application | qemu | qemu | 9.0.0 | Yes |
Application | qemu | qemu | 9.0.0 | Yes |
Operating System | redhat | enterprise_linux | 9.0 | Yes |