Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-24474

Published: 20 February 2024

QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the length of the available FIFO data. This occurs in esp_do_nodma in hw/scsi/esp.c because of an underflow of async_len.

Priority

Medium

Status

Package Release Status
qemu
Launchpad, Ubuntu, Debian
bionic Needs triage

focal Needed

jammy Needed

mantic Needed

noble Not vulnerable
(1:8.2.1+ds-1ubuntu1)
trusty Needs triage

upstream
Released (8.2.0)
xenial Needs triage

Patches:
upstream: https://github.com/qemu/qemu/commit/77668e4b9bca03a856c27ba899a2513ddf52bb52