REDHAT-BUG-2274339: Medium severity qemu vulnerability
An assertion failure issue was found in the updatesctpchecksum() function in hw/net/nettxpkt.c when trying to calculate the checksum of a short-sized fragmented packet. A malicious guest could use this flaw to crash QEMU and cause a denial of service condition.
Upstream issue & patch: https://gitlab.com/qemu-project/qemu/-/issues/2273 https://patchew.org/QEMU/20240410070459.49112-1-philmd@linaro.org/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2274339?
The severity of REDHAT-BUG-2274339 is critical due to the potential denial of service it can cause.
How do I fix REDHAT-BUG-2274339?
To fix REDHAT-BUG-2274339, you should apply the latest patches provided by QEMU.
What is the impact of REDHAT-BUG-2274339?
The impact of REDHAT-BUG-2274339 is that a malicious guest could crash QEMU, leading to a denial of service.
Which software is affected by REDHAT-BUG-2274339?
REDHAT-BUG-2274339 affects QEMU, specifically versions that utilize the update_sctp_checksum() function in hw/net/net_tx_pkt.c.
Is there a known workaround for REDHAT-BUG-2274339?
Currently, there are no documented workarounds for REDHAT-BUG-2274339 other than updating to the patched version of QEMU.