First published: Fri Aug 04 2023(Updated: )
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/qemu-kvm | <8.1.0 | 8.1.0 |
ubuntu/qemu | <1:8.0.4+dfsg-1ubuntu3.23.10.2 | 1:8.0.4+dfsg-1ubuntu3.23.10.2 |
debian/qemu | 1:5.2+dfsg-11+deb11u3 1:5.2+dfsg-11+deb11u2 1:7.2+dfsg-7+deb12u7 1:9.0.2+ds-2 1:9.1.0+ds-3 | |
QEMU KVM | >=8.0.0<8.1.0 | |
QEMU KVM | =8.1.0-rc0 | |
QEMU KVM | =8.1.0-rc1 | |
QEMU KVM | =8.1.0-rc2 | |
Fedoraproject Fedora | =38 | |
QEMU KVM | ||
QEMU KVM | <2023-08-03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4135 is a heap out-of-bounds memory read flaw found in the virtual nvme device in QEMU.
CVE-2023-4135 has a severity of medium.
The QEMU QEMU, Fedoraproject Fedora 38, and redhat/qemu-kvm versions up to 8.1.0 are affected by CVE-2023-4135.
To fix CVE-2023-4135, update to the latest version of QEMU, Fedoraproject Fedora 38, or redhat/qemu-kvm.
The CWE ID of CVE-2023-4135 is 125.