« List of all CVEs

CVE-2023-3019

Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()

Published: 7/24/2023 Last updated: 1/27/2026 Reserved: 5/31/2023

A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 6 Medium CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Opam packages affected (2)

conf-qemu-img nbd-tool

Products affected (18)

Product Vendor Version
Red Hat Enterprise Linux 6 Red Hat 1.2.0.14
Red Hat Enterprise Linux 9 Red Hat 6.6.0
Red Hat Enterprise Linux 7 Red Hat 20.1.1.1
Red Hat Enterprise Linux 7 Red Hat FastConnect 7800
Red Hat Enterprise Linux 6 Red Hat FastConnect 6900
Red Hat Enterprise Linux 9 Red Hat FastConnect 6700
Red Hat Enterprise Linux 7 Red Hat QCA6698AQ
Red Hat Enterprise Linux 7 Red Hat X12.5.1
Red Hat Enterprise Linux 8 Advanced Virtualization Red Hat QCM5430
Red Hat Enterprise Linux 8 Advanced Virtualization Red Hat 6.4.0.14
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat <= 2.0.0
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat 15.0(1)XA
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat 6.5.28
Red Hat Enterprise Linux 8 Red Hat 6.4.0.13
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat 23.0 ap373015
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat <= 2.7.5
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat CSRA6620
Red Hat Enterprise Linux 8 Red Hat SA8150P

References (28)