A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU proce
A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU…
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | 8100020240905091210.489197e6 |
| Red Hat | Red Hat Enterprise Linux 8 | 8100020240905091210.489197e6 |
| Red Hat | Red Hat Enterprise Linux 6 | unspecified |
| Red Hat | Red Hat Enterprise Linux 7 | unspecified |
| Red Hat | Red Hat Enterprise Linux 7 | unspecified |
| Red Hat | Red Hat Enterprise Linux 8 Advanced Virtualization | unspecified |
| Red Hat | Red Hat Enterprise Linux 9 | unspecified |
Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.