CVE-2024-7730
Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()
Published:
11/14/2024
Last updated:
11/14/2024
Reserved:
8/13/2024
A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for audio data zero.
CNA assigner:
fedora (92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5)
Requested by:
n/a
Products affected (7)
| Product |
Vendor |
Version |
|
|
SG4150P
|
| Red Hat Enterprise Linux 9 |
Red Hat
|
SM7325P
|
| Red Hat Enterprise Linux 6 |
Red Hat
|
< eed04fa96c48790c1cce73c8a248e9d460b088f8
|
| Red Hat Enterprise Linux 7 |
Red Hat
|
All versions < V4.4
|
| Red Hat Enterprise Linux 7 |
Red Hat
|
Adobe Acrobat Reader 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier.
|
| Red Hat Enterprise Linux 8 Advanced Virtualization |
Red Hat
|
< 5.10.216
|
| Red Hat Enterprise Linux 8 |
Red Hat
|
SM7250P
|