Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors in which the value of curr_queues is greater than max_queues, which triggers an out-of-bounds write.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
QEMU 缓冲区错误漏洞
Vulnerability Description
QEMU是法国Fabrice Bellard个人开发者的一套模拟处理器软件。该软件具有速度快、跨平台等特点。ecto是elixir-ecto开源的一个用于数据映射和语言集成查询的工具包。 QEMU 1.5.0版本至1.7.2之前1.7.x版本存在缓冲区错误漏洞,该漏洞源于程序没有正确检查curr_queues值的大小。远程攻击者可利用该漏洞造成拒绝服务或执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A