Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest crash) and possibly execute arbitrary code by sending a crafted value to the 0xae08 (PCI_EJ_BASE) I/O port, which leads to a use-after-free related to "active qemu timers."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Qemu-Kvm 输入验证错误漏洞
Vulnerability Description
Qemu-Kvm是软件自由保护协会(Software Freedom Conservancy)组织的一种开源的、目前最流行的虚拟化技术。 Qemu-Kvm中存在输入验证错误漏洞。该漏洞是由于PIIX4仿真不使用non-hotpluggable PCI设备导致的,本地用户可以利用该漏洞解引用无效内存并执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A