« List of all CVEs

CVE-2023-3019

Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()

Published: 7/24/2023 Last updated: 11/6/2025 Reserved: 5/31/2023

A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 6 Medium CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Opam packages affected (2)

conf-qemu-img nbd-tool

Products affected (17)

Product Vendor Version
Red Hat Enterprise Linux 7 Red Hat < 10.0.14393.7336
Red Hat Enterprise Linux 7 Red Hat 12.4(24)MDB8
Red Hat Enterprise Linux 9 Red Hat Modem LR12A, LR13, NR15, NR16, NR17, NR17R
Red Hat Enterprise Linux 6 Red Hat <= 8.0.34
Red Hat Enterprise Linux 7 Red Hat n/a
Red Hat Enterprise Linux 7 Red Hat 8.1.0
Red Hat Enterprise Linux 8 Advanced Virtualization Red Hat n/a
Red Hat Enterprise Linux 8 Advanced Virtualization Red Hat < publication
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat n/a
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat < ff39adf5d31c72025bba799aec69c5c86d81d549
Red Hat Enterprise Linux 8 Red Hat n/a
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat 15.0(2)SG5
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat 12.2(33)SCE
Red Hat Enterprise Linux 8 Red Hat < 10.0.14393.7336

References (28)