RHSA-2024:0404HighCVSS 7.5
Red Hat Security Advisory: virt:rhel and virt-devel:rhel security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-3750 — QEMU: hcd-ehci: DMA reentrancy issue leads to use-after-free CVE-2022-40284 — NTFS-3G: buffer overflow issue in NTFS-3G can cause code execution via crafted metadata in an NTFS image CVE-2023-3019 — QEMU: e1000e: heap use-after-free in e1000e_write_packet_to_guest() CVE-2023-3354 — QEMU: VNC: improper I/O watch removal in TLS handshake can lead to remote unauthenticated denial of service
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:0404
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999073
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2216478
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222351
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236130
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0404.json