Database/Kernel, userspace & hypervisor
QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU process
CVSS 7.5CVE-2021-3748Kernel, userspace & hypervisorcurated
Impact
Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU process
Who can reach it
Tenant VM guest
What to do
QEMU package update + restart each VM's qemu process. Live-migrate to patched hosts to avoid tenant downtime; GPU-passthrough VMs cannot live-migrate, so this becomes a scheduled drain
References
Related entries
- QEMU (virtio-net): Map leaking on error during receive - guest-triggered host memory exhaustion / DoSCVE-2022-26353 · QEMU (virtio-net)High
- Linux kernel (drivers/nvme/target): When the target's peer-to-peer memory pool runs dry, it still tries to return theCVE-2021-47130 · Linux kernel (drivers/nvme/target)High
- OpenSSL 3.0: X.509 email-address punycode buffer overflow (4-byte stack overflow)CVE-2022-3602 · OpenSSL 3.0High
- OpenSSL 3.0: X.509 email-address variable-length buffer overflow (DoS)CVE-2022-3786 · OpenSSL 3.0High
- AMD CPU (Sinkclose): Sinkclose: SMM lock bypassCVE-2023-31315 · AMD CPU (Sinkclose)High
- Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.c: A host sending an H2CData command with a DATALCVE-2023-52454 · Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.cHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.