« List of all CVEs

CVE-2023-3301

Triggerable assertion due to race condition in hot-unplug

Published: 9/13/2023 Last updated: 2/13/2025 Reserved: 6/17/2023

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.6 Medium CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

Opam packages affected (2)

conf-qemu-img nbd-tool

Products affected (10)

Product Vendor Version
Extra Packages for Enterprise Linux Fedora 4.1.4
Fedora Fedora < publication
Red Hat Enterprise Linux 6 Red Hat APQ8017
Red Hat Enterprise Linux 7 Red Hat <= *
Red Hat Enterprise Linux 9 Red Hat <= None
Red Hat Enterprise Linux 7 Red Hat AR8035
Red Hat OpenStack Platform 13 (Queens) Red Hat < publication
Red Hat Enterprise Linux 8 Advanced Virtualization Red Hat <= 17.4
Red Hat Enterprise Linux 8 Red Hat CSRA6640
qemu n/a n/a

References (6)

Credits (1)