VYPR
High severity7.5NVD Advisory· Published Jul 11, 2023· Updated Jun 17, 2026

CVE-2023-3354

CVE-2023-3354

Description

A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

179

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.