Vulnerability CVE-2023-42467: Information
Description
QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately.
Severity: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
qemu | sisyphus | 8.1.2-alt1 | 8.2.3-alt1 | ALT-PU-2023-6573-1 | 332089 | Fixed |
qemu | sisyphus_loongarch64 | 8.1.3-alt0.port | 8.2.3-alt1 | ALT-PU-2023-8102-1 | - | Fixed |
qemu | p10 | 8.0.4-alt1.p10 | 8.2.2-alt0.p10.1 | ALT-PU-2023-5241-3 | 328289 | Fixed |
qemu | c10f1 | 8.0.4-alt1.p10 | 8.2.2-alt0.p10.1 | ALT-PU-2023-7183-2 | 334310 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://gitlab.com/qemu-project/qemu/-/issues/1813 |
|
https://gitlab.com/qemu-project/qemu/-/commit/7cfcc79b0ab800959716738aff9419f53fc68c9c | |
https://security.netapp.com/advisory/ntap-20231103-0005/ |