THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-24474

Reserved:2024-01-25
Published:2024-02-20
Updated:2024-06-10

Description

QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the length of the available FIFO data. This occurs in esp_do_nodma in hw/scsi/esp.c because of an underflow of async_len.

References

https://gitlab.com/qemu-project/qemu/-/issues/1810

https://github.com/qemu/qemu/commit/77668e4b9bca03a856c27ba899a2513ddf52bb52

https://gist.github.com/1047524396/5ce07b9d387095c276b1cd234ae5615e

https://security.netapp.com/advisory/ntap-20240510-0012/

cve.org CVE-2024-24474

nvd.nist.gov CVE-2024-24474

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-24474