REDHAT-BUG-2292089: Use After Free
There is an use-after-free vulnerability in QEMU LSI53C895A SCSI Host Bus Adapter emulation, which can lead to VM escape. The crash noticed in this case is an write to freed memory. But given the complexity of the freed structure, multiple primitives like dereferencing function pointers, etc., should be possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2292089?
REDHAT-BUG-2292089 is considered a critical vulnerability due to the potential for VM escape.
How do I fix REDHAT-BUG-2292089?
To fix REDHAT-BUG-2292089, update your QEMU installation to the latest patched version that addresses this vulnerability.
What systems are affected by REDHAT-BUG-2292089?
REDHAT-BUG-2292089 affects systems running QEMU with LSI53C895A SCSI Host Bus Adapter emulation.
What could happen if REDHAT-BUG-2292089 is exploited?
Exploitation of REDHAT-BUG-2292089 can result in a system crash or allow an attacker to escape the guest VM environment.
Is there a workaround for REDHAT-BUG-2292089?
Currently, there are no officially recommended workarounds for REDHAT-BUG-2292089, and the best action is to apply updates.