« List of all CVEs

CVE-2024-3567

Qemu-kvm: net: assertion failure in update_sctp_checksum()

Published: 4/10/2024 Last updated: 5/6/2025 Reserved: 4/10/2024

A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.5 Medium CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Opam packages affected (2)

conf-qemu-img nbd-tool

Products affected (7)

Product Vendor Version
n/a
Red Hat Enterprise Linux 9 Red Hat <= 04.03.03 (72)
Red Hat Enterprise Linux 6 Red Hat < 1fc793d68d50dee4782ef2e808913d5dd880bcc6
Red Hat Enterprise Linux 7 Red Hat n/a
Red Hat Enterprise Linux 7 Red Hat < 21.2R3-S6
Red Hat Enterprise Linux 8 Advanced Virtualization Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat n/a

References (8)