First published: Wed Jun 12 2024(Updated: )
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6519 is considered to have a high severity due to its potential for VM escape and system crashes.
CVE-2024-6519 affects the QEMU KVM environment specifically targeting the LSI53C895A SCSI Host Bus Adapter.
To fix CVE-2024-6519, you should update QEMU to the latest version that addresses this vulnerability.
CVE-2024-6519 can potentially be exploited remotely if the affected QEMU configuration is exposed to untrusted users.
Not addressing CVE-2024-6519 can lead to crashes or allow attackers to escape the virtual machine environment, compromising host security.