CVE-2024-7730
Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()
Published:
11/14/2024
Last updated:
11/14/2024
Reserved:
8/13/2024
A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for audio data zero.
CNA assigner:
fedora (92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5)
Requested by:
n/a
Products affected (1)
| Product |
Vendor |
Version |
| Red Hat Enterprise Linux 9 |
Red Hat
|
< 9d0a330abd9e49bcebf6307aac185081bde49a43
|