Security Advisory

CVE-2024-3446

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-04-09 19:34:45
Last updated 2025-05-02 23:02:59
Assigner redhat
State PUBLISHED

Description

A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.