Unrated severityNVD Advisory· Published Aug 3, 2023· Updated Sep 25, 2024
Heap buffer overflow in virtio_crypto_sym_op_helper()
CVE-2023-3180
Description
A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of src_len and dst_len in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- access.redhat.com/security/cve/CVE-2023-3180mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
- lists.debian.org/debian-lts-announce/2023/10/msg00006.htmlmitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MURWGXDIF2WTDXV36T6HFJDBL632AO7R/mitre
- security.netapp.com/advisory/ntap-20230831-0008/mitre
News mentions
0No linked articles in our index yet.