CVE-2023-4135
04.08.2023, 14:15
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.Enginsight
Vendor | Product | Version |
---|---|---|
qemu | qemu | 8.0.0 ≤ 𝑥 < 8.1.0 |
qemu | qemu | 8.1.0:rc0 |
qemu | qemu | 8.1.0:rc1 |
qemu | qemu | 8.1.0:rc2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References