A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
| Version | Score | Severity | Vector String |
|---|---|---|---|
| 3.1 | 6 | Medium | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
| Product | Vendor | Version |
|---|---|---|
| Fedora | Fedora | 15.2(6)E2b |
| Extra Packages for Enterprise Linux | Fedora | 22.0 ap372643 |
| Red Hat Enterprise Linux 6 | Red Hat | 22.0 ap370654 |
| Red Hat Enterprise Linux 7 | Red Hat | ArubaOS 8.11.x.x: 8.11.2.0 and below |
| Red Hat Enterprise Linux 9 | Red Hat | 22.0 ap370615 |
| Red Hat Enterprise Linux 7 | Red Hat | 22.0 ap370138 |
| Red Hat Enterprise Linux 8 | Red Hat | ArubaOS 8.10.x.x: 8.10.0.9 and below |
| qemu-kvm | n/a | ArubaOS 10.4.x.x: 10.4.0.3 and below |