We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-24474



Description

QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the length of the available FIFO data. This occurs in esp_do_nodma in hw/scsi/esp.c because of an underflow of async_len.

Reserved 2024-01-25 | Published 2024-02-20 | Updated 2024-08-15 | Assigner mitre

References

gitlab.com/qemu-project/qemu/-/issues/1810

github.com/...ommit/77668e4b9bca03a856c27ba899a2513ddf52bb52

gist.github.com/1047524396/5ce07b9d387095c276b1cd234ae5615e

security.netapp.com/advisory/ntap-20240510-0012/

cve.org (CVE-2024-24474)

nvd.nist.gov (CVE-2024-24474)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-24474

Support options

Helpdesk Chat, Email, Knowledgebase