CVE-2024-4693: Qemu-kvm: virtio-pci: improper release of configure vector leads to guest triggerable crash
A flaw was found in QEMU in the Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhostnetstop().
The original patch [1] was found to be incomplete and is currently being reworked upstream [2][3].
[1] https://gitlab.com/qemu-project/qemu/-/commit/fcbb086ae590e910614fe5b8bf76e264f71ef304 [2] https://gitlab.com/qemu-project/qemu/-/issues/2321 [3] https://gitlab.com/qemu-project/qemu/-/issues/2334
Other sources
A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhostnetstop(). This flaw allows a malicious guest to crash the QEMU process on the host.
— Launchpad
Qemu-kvm: virtio-pci: improper release of configure vector leads to guest triggerable crash
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qemuto a version that resolves this vulnerability.Fixed in 1:5.2+dfsg-11+deb11u3Fixed in 1:5.2+dfsg-11+deb11u2Fixed in 1:7.2+dfsg-7+deb12u12Fixed in 1:9.2.2+ds-1Fixed in 1:10.0.0~rc2+ds-2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4693?
CVE-2024-4693 is classified as a critical severity vulnerability due to the potential guest-triggered crash.
How do I fix CVE-2024-4693?
To resolve CVE-2024-4693, update QEMU to the latest patched version provided by your distribution.
What software is affected by CVE-2024-4693?
CVE-2024-4693 affects specific versions of QEMU in Debian, including versions 1:5.2+dfsg-11+deb11u3 and others.
What can happen if CVE-2024-4693 is exploited?
Exploitation of CVE-2024-4693 may lead to a denial of service condition by causing the QEMU guest to crash.
Is there a workaround for CVE-2024-4693?
Currently, there is no official workaround for CVE-2024-4693 other than applying the necessary software updates.