VYPR
Unrated severityNVD Advisory· Published Aug 3, 2023· Updated Sep 25, 2024

Heap buffer overflow in virtio_crypto_sym_op_helper()

CVE-2023-3180

Description

A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of src_len and dst_len in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.