There is a vulnerability in the lsi53c895a device which affects the latest version of qemu. The carefully designed PoC can repeatedly trigger DMA writes but does not limit the addresses written to the DMA, resulting in reentrancy issues and eventually overflow.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Core | qemu | 2023-07-17 17:40 | ALAS2-2023-2148 |
Amazon Linux 2 - Core | qemu | 2023-08-03 18:10 | ALAS2-2023-2191 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 5.3 | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H |
NVD | CVSSv3 | 6.0 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H |