VYPR
Medium severity6.0NVD Advisory· Published Aug 4, 2023· Updated Jun 17, 2026

CVE-2023-4135

CVE-2023-4135

Description

A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13
  • cpe:/a:redhat:advanced_virtualization:8::el8
  • Red Hat/Enterprise Linux Servercpe-rescue4 versions
    cpe:/o:redhat:enterprise_linux:6+ 3 more
    • cpe:/o:redhat:enterprise_linux:6
    • cpe:/o:redhat:enterprise_linux:7
    • cpe:/o:redhat:enterprise_linux:8
    • cpe:/o:redhat:enterprise_linux:9
  • QEMU/Qemu5 versions
    cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*range: >=8.0.0,<8.1.0
    • cpe:2.3:a:qemu:qemu:8.1.0:rc0:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:8.1.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:8.1.0:rc2:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
  • Fedora/Extra Packages for Enterprise Linuxv5

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.