CVE-2024-6505

Source
https://cve.org/CVERecord?id=CVE-2024-6505
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6505.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-6505
Downstream
AZL (2)
CGA (28)
DEBIAN (1)
OESA (4)
SUSE (3)
UBUNTU (1)
Related
Published
2024-07-05T13:51:38Z
Modified
2026-08-12T03:51:35Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H CVSS Calculator
Summary
Qemu-kvm: virtio-net: queue index out-of-bounds access in software rss
Details

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-125"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6505.json"
}
References

Affected packages

Git / github.com/qemu/qemu

Affected ranges

Type
GIT
Repo
https://github.com/qemu/qemu
Events
Database specific
Show details
{
    "cpe":  [
        "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*"
    ],
    "extracted_events":  [
        {
            "introduced":  "8.0"
        },
        {
            "last_affected":  "8.0"
        },
        {
            "introduced":  "9.0"
        },
        {
            "last_affected":  "9.0"
        }
    ],
    "source":  "CPE_STRING"
}
Type
GIT
Repo
https://gitlab.com/qemu-project/qemu
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "5.1.0"
        },
        {
            "fixed":  "9.1.0"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

8.*
8.0
9.*
9.0
v5.*
v5.1.0
v5.2.0
v5.2.0-rc0
v5.2.0-rc1
v5.2.0-rc2
v5.2.0-rc3
v5.2.0-rc4
v6.*
v6.0.0
v6.0.0-rc0
v6.0.0-rc1
v6.0.0-rc2
v6.0.0-rc3
v6.0.0-rc4
v6.0.0-rc5
v6.1.0
v6.1.0-rc0
v6.1.0-rc1
v6.1.0-rc2
v6.1.0-rc3
v6.1.0-rc4
v6.2.0
v6.2.0-rc0
v6.2.0-rc1
v6.2.0-rc3
v6.2.0-rc4
v7.*
v7.0.0
v7.0.0-rc0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v7.0.0-rc4
v7.1.0
v7.1.0-rc0
v7.1.0-rc1
v7.1.0-rc2
v7.1.0-rc3
v7.1.0-rc4
v7.2.0
v7.2.0-rc0
v7.2.0-rc1
v7.2.0-rc2
v7.2.0-rc3
v7.2.0-rc4
v8.*
v8.0.0
v8.0.0-rc0
v8.0.0-rc1
v8.0.0-rc2
v8.0.0-rc3
v8.0.0-rc4
v8.1.0
v8.1.0-rc0
v8.1.0-rc1
v8.1.0-rc2
v8.1.0-rc3
v8.1.0-rc4
v8.2.0
v8.2.0-rc0
v8.2.0-rc1
v8.2.0-rc2
v8.2.0-rc3
v8.2.0-rc4
v9.*
v9.0.0
v9.0.0-rc0
v9.0.0-rc1
v9.0.0-rc2
v9.0.0-rc3
v9.0.0-rc4
v9.1.0-rc0
v9.1.0-rc1
v9.1.0-rc2
v9.1.0-rc3
v9.1.0-rc4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6505.json"