OSV-2023-390

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/qemu/OSV-2023-390.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2023-390
Published
2023-05-12T14:00:08.854823Z
Modified
2024-12-04T14:44:03.226338Z
Summary
Heap-buffer-overflow in sdhci_write
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=58813

Crash type: Heap-buffer-overflow WRITE 1
Crash state:
sdhci_write
memory_region_write_accessor
memory_region_dispatch_write
References

Affected packages

OSS-Fuzz / qemu

Package

Name
qemu
Purl
pkg:generic/qemu

Affected ranges

Type
GIT
Repo
https://git.qemu.org/git/qemu.git
Events
Introduced
b7a3a705b644495b7b578e94e0e9dedf93c4f661

Affected versions

v7.*

v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v7.0.0-rc4
v7.1.0
v7.1.0-rc0
v7.1.0-rc1
v7.1.0-rc2
v7.1.0-rc3
v7.1.0-rc4
v7.2.0
v7.2.0-rc0
v7.2.0-rc1
v7.2.0-rc2
v7.2.0-rc3
v7.2.0-rc4
v7.2.1
v7.2.10
v7.2.11
v7.2.12
v7.2.13
v7.2.14
v7.2.15
v7.2.2
v7.2.3
v7.2.4
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9

v8.*

v8.0.0
v8.0.0-rc0
v8.0.0-rc1
v8.0.0-rc2
v8.0.0-rc3
v8.0.0-rc4
v8.0.1
v8.0.2
v8.0.3
v8.0.4
v8.0.5
v8.1.0
v8.1.0-rc0
v8.1.0-rc1
v8.1.0-rc2
v8.1.0-rc3
v8.1.0-rc4
v8.1.1
v8.1.2
v8.1.3
v8.1.4
v8.1.5
v8.2.0
v8.2.0-rc0
v8.2.0-rc1
v8.2.0-rc2
v8.2.0-rc3
v8.2.0-rc4
v8.2.1
v8.2.2
v8.2.3
v8.2.4
v8.2.5
v8.2.6
v8.2.7
v8.2.8

v9.*

v9.0.0
v9.0.0-rc0
v9.0.0-rc1
v9.0.0-rc2
v9.0.0-rc3
v9.0.0-rc4
v9.0.1
v9.0.2
v9.0.3
v9.0.4
v9.1.0
v9.1.0-rc0
v9.1.0-rc1
v9.1.0-rc2
v9.1.0-rc3
v9.1.0-rc4
v9.1.1
v9.1.2
v9.2.0-rc0
v9.2.0-rc1
v9.2.0-rc2
v9.2.0-rc3

Ecosystem specific

{
    "severity": "MEDIUM"
}