An issue was discovered in QEMU 7.1.0 through 8.2.1. The register_vfs() function in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations. Reference: https://lore.kernel.org/all/20240214-reuse-v4-5-89ad093a07f4@daynix.com/
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 2264845]
Upstream commit: https://gitlab.com/qemu-project/qemu/-/commit/6081b4243cd64dff1b2cf5b0c215c71e9d7e753b
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9136 https://access.redhat.com/errata/RHSA-2024:9136