Database/Kernel, userspace & hypervisor
QEMU (NBD server): Improper synchronisation during socket closure - DoS of the QEMU NBD server
CVSS 7.5CVE-2024-7409Kernel, userspace & hypervisorcurated
Impact
Improper synchronisation during socket closure - DoS of the QEMU NBD server
Who can reach it
Unauthenticated network to the NBD port; tenant VM guest
What to do
QEMU update + restart; do not expose NBD to tenant networks
References
Related entries
- QEMU: use-after-free in the VNC WebSocket handshake crashes the VM process before client authenticationCVE-2025-11234 · QEMU QIOChannelWebsock (VNC WebSocket handshake)High
- Linux kernel (net/tls): If a page allocation fails while the TLS strparser is copying a partial record, the receiveCVE-2025-38018 · Linux kernel (net/tls)High
- Linux kernel (drivers/nvme/target): A connecting client that abandons the TCP connection at the right moment duringCVE-2025-38035 · Linux kernel (drivers/nvme/target)High
- Linux kernel (net/xfrm): Several error paths in the ESP-in-TCP receive code return without freeing the skb, soCVE-2025-38057 · Linux kernel (net/xfrm)High
- Linux kernel (drivers/nvme/target): Every command a client sends to the target carrying metadata (protectionCVE-2025-38405 · Linux kernel (drivers/nvme/target)High
- Linux kernel mlx5_core IPsec RX offload: When hardware reports an xfrm state ID for a decrypted packet whose stateCVE-2025-38590 · Linux kernel mlx5_core IPsec RX offloadHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.