CVE-2024-7730: Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()

Published Aug 13, 2024
·
Updated

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtiosndpcmincb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtiosndpcmstatus, which makes the available space for audio data zero.

Other sources

Qemu-kvm: virtio-snd: heap buffer overflow in virtiosndpcmincb()

Microsoft

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

When reading input audio in the virtio-snd input callback, virtiosndpcmincb(), we do not check whether the iov can actually fit the data buffer. This is because we use the buffer->size field as a total-so-far accumulator instead of byte-size-left like in TX buffers.

This triggers an out of bounds write if the size of the virtio queue element is equal to virtiosndpcmstatus, which makes the available space for audio data zero. This commit adds a check for reaching the maximum buffer size before attempting any writes.

Reference: https://lore.kernel.org/qemu-devel/virtio-snd-fuzz-2427-fix-v1-manos.pitsidianakis@linaro.org/

Upstream issue: https://gitlab.com/qemu-project/qemu/-/issues/2427

Upstream fix: https://gitlab.com/qemu-project/qemu/-/commit/98e77e3dd8dd6e7aa9a7dffa60f49c8c8a49d4e3

Red Hat

Affected Software

3 affected componentsFixes available
debian/qemu<=1:5.2+dfsg-11+deb11u3, <=1:5.2+dfsg-11+deb11u2, <=1:7.2+dfsg-7+deb12u12
1:10.0.0~rc2+ds-21:10.0.0~rc3+ds-2
Qemu Qemu<9.1.0
Microsoft azl3 qemu 8.2.0-16

Event History

Aug 13, 2024
Data Sourced
via Red Hat·09:50 AM
DescriptionSeverityAffected Software
Nov 11, 2024
Data Sourced
via Launchpad·12:43 AM
Description
Nov 14, 2024
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
Affected Software
Nov 23, 2024
Data Sourced
via Ubuntu·12:44 AM
RemedyDescriptionSeverityAffected Software
May 6, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2024-7730?

CVE-2024-7730 has a high severity rating due to the potential for a heap buffer overflow that can lead to out-of-bounds write vulnerabilities.

2

How do I fix CVE-2024-7730?

To fix CVE-2024-7730, update to the patched version of QEMU, specifically version 1:9.2.0+ds-5 or later.

3

Which versions of QEMU are affected by CVE-2024-7730?

CVE-2024-7730 affects QEMU versions up to and including 1:5.2+dfsg-11+deb11u3, 1:5.2+dfsg-11+deb11u2, and 1:7.2+dfsg-7+deb12u12.

4

What components are impacted by CVE-2024-7730?

CVE-2024-7730 impacts the virtio-snd device within QEMU, particularly during the audio input read operations.

5

Is CVE-2024-7730 an exploitative vulnerability?

Yes, CVE-2024-7730 can potentially be exploited to execute arbitrary code due to the heap buffer overflow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203