In QEMU 3.1, scsihandleinquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
{ "urgency": "not yet assigned" }