USN-6954-1: QEMU vulnerabilities
Markus Frank and Fiona Ebner discovered that QEMU did not properly handle certain memory operations, leading to a NULL pointer dereference. An authenticated user could potentially use this issue to cause a denial of service. (CVE-2023-6683) Xiao Lei discovered that QEMU did not properly handle certain memory operations when specific features were enabled, which could lead to a stack overflow. An attacker could potentially use this issue to leak sensitive information. (CVE-2023-6693) It was discovered that QEMU had an integer underflow vulnerability in the TI command, which would result in a buffer overflow. An attacker could potentially use this issue to cause a denial of service. (CVE-2024-24474)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6954-1?
The severity of USN-6954-1 is categorized as a denial of service vulnerability that could be exploited by an authenticated user.
How do I fix USN-6954-1?
To fix USN-6954-1, you should upgrade the affected packages to version 1:6.2+dfsg-2ubuntu6.22 or later.
What products are affected by USN-6954-1?
USN-6954-1 affects multiple QEMU packages on Ubuntu 22.04, including qemu-system, qemu-system-arm, qemu-system-mips, and others.
Who discovered the vulnerability identified in USN-6954-1?
The USN-6954-1 vulnerability was discovered by Markus Frank and Fiona Ebner.
Can USN-6954-1 be exploited remotely?
No, USN-6954-1 requires an authenticated local user to exploit the denial of service vulnerability.