hw/rdma/rdmabackend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large numsge value.
{ "urgency": "unimportant" }