Bug 2279965 (CVE-2024-4693) - CVE-2024-4693 qemu-kvm: virtio-pci: improper release of configure vector leads to guest triggerable crash
Summary: CVE-2024-4693 qemu-kvm: virtio-pci: improper release of configure vector lead...
Keywords:
Status: NEW
Alias: CVE-2024-4693
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2279966
Blocks: 2279968
TreeView+ depends on / blocked
 
Reported: 2024-05-10 08:48 UTC by Mauro Matteo Cascella
Modified: 2024-08-13 09:44 UTC (History)
12 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Mauro Matteo Cascella 2024-05-10 08:48:44 UTC
A flaw was found in QEMU in the Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop().

The original patch [1] was found to be incomplete and is currently being reworked upstream [2][3].

[1] https://gitlab.com/qemu-project/qemu/-/commit/fcbb086ae590e910614fe5b8bf76e264f71ef304
[2] https://gitlab.com/qemu-project/qemu/-/issues/2321
[3] https://gitlab.com/qemu-project/qemu/-/issues/2334

Comment 1 Mauro Matteo Cascella 2024-05-10 08:49:34 UTC
Created qemu tracking bugs for this issue:

Affects: fedora-all [bug 2279966]

Comment 3 Mauro Matteo Cascella 2024-06-12 12:58:15 UTC
Upstream commit:
https://gitlab.com/qemu-project/qemu/-/commit/7eeb62b0ce3a8f64647bf53f93903abd1fbb0b94


Note You need to log in before you can comment on or make changes to this bug.