« List of all CVEs

CVE-2023-3019

Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()

Published: 7/24/2023 Last updated: 5/12/2026 Reserved: 5/31/2023

A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 6 Medium CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Opam packages affected (2)

conf-qemu-img nbd-tool

Products affected (16)

Product Vendor Version
Red Hat Enterprise Linux 7 Red Hat 9.0.0.29935
Red Hat Enterprise Linux 6 Red Hat Firmware version 0.20.17
Red Hat Enterprise Linux 9 Red Hat n/a
Red Hat Enterprise Linux 7 Red Hat n/a
Red Hat Enterprise Linux 7 Red Hat 7 for x64-based Systems Service Pack 1
Red Hat Enterprise Linux 7 Red Hat 7.5.2.17
Red Hat Enterprise Linux 8 Advanced Virtualization Red Hat 8.1 for x64-based systems
Red Hat Enterprise Linux 8 Advanced Virtualization Red Hat 7.5.0.0
Red Hat Enterprise Linux 8 Red Hat EDK II
Red Hat Enterprise Linux 8 Red Hat < unspecified
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat Windows 10 Version 1709 for x64-based Systems
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat Windows Server 2016
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat n/a

References (30)