Reachable assertion in QEMU - CVE-2024-3567

 

Reachable assertion in QEMU - CVE-2024-3567

Published: July 18, 2024


Vulnerability identifier: #VU94529
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-3567
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a malicious guest to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion within the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. A malicious guest can crash the QUEMU process.


Affected software

QEMU
Ubuntu
Anolis OS
qemu (Ubuntu package)
qemu-ui-opengl
qemu-guest-agent
qemu-img
qemu-kvm
qemu-kvm-core
qemu-pr-helper
qemu-system-x86
qemu-system-x86-core
qemu-tests
qemu-tools
qemu-ui-curses
qemu-ui-dbus
qemu-ui-egl-headless
qemu-ui-gtk
qemu-docs
qemu-ui-spice-app
qemu-ui-spice-core
qemu-user
qemu-user-binfmt
qemu-system-aarch64
qemu-system-aarch64-core
qemu-block-rbd
qemu-system-loongarch64
qemu-system-loongarch64-core
qemu-system-riscv
qemu-system-riscv-core
qemu-device-usb-smartcard
qemu
qemu-audio-alsa
qemu-audio-dbus
qemu-audio-oss
qemu-audio-pa
qemu-audio-spice
qemu-block-curl
qemu-block-dmg
qemu-block-gluster
qemu-block-iscsi
qemu-block-ssh
qemu-char-baum
qemu-char-spice
qemu-common
qemu-device-display-qxl
qemu-device-display-virtio-gpu
qemu-device-display-virtio-gpu-ccw
qemu-device-display-virtio-gpu-pci
qemu-device-display-virtio-vga
qemu-device-display-virtio-vga-gl
qemu-device-usb-host
qemu-device-usb-redirect

How to mitigate CVE-2024-3567

Install updates from vendor's website.

QEMU - update to 8.2.3
qemu (Ubuntu package) - addressed in versions 1:6.2+dfsg-2ubuntu6.27, 1:8.2.2+ds-0ubuntu1.10, 1:9.2.1+ds-1ubuntu5.2
qemu-ui-opengl - update to 8.2.0-33
qemu-guest-agent - update to 8.2.0-33
qemu-img - update to 8.2.0-33
qemu-kvm - update to 8.2.0-33
qemu-kvm-core - update to 8.2.0-33
qemu-pr-helper - update to 8.2.0-33
qemu-system-x86 - update to 8.2.0-33
qemu-system-x86-core - update to 8.2.0-33
qemu-tests - update to 8.2.0-33
qemu-tools - update to 8.2.0-33
qemu-ui-curses - update to 8.2.0-33
qemu-ui-dbus - update to 8.2.0-33
qemu-ui-egl-headless - update to 8.2.0-33
qemu-ui-gtk - update to 8.2.0-33
qemu-docs - update to 8.2.0-33
qemu-ui-spice-app - update to 8.2.0-33
qemu-ui-spice-core - update to 8.2.0-33
qemu-user - update to 8.2.0-33
qemu-user-binfmt - update to 8.2.0-33
qemu-system-aarch64 - update to 8.2.0-33
qemu-system-aarch64-core - update to 8.2.0-33
qemu-block-rbd - update to 8.2.0-33
qemu-system-loongarch64 - update to 8.2.0-33
qemu-system-loongarch64-core - update to 8.2.0-33
qemu-system-riscv - update to 8.2.0-33
qemu-system-riscv-core - update to 8.2.0-33
qemu-device-usb-smartcard - update to 8.2.0-33
qemu - update to 8.2.0-33
qemu-audio-alsa - update to 8.2.0-33
qemu-audio-dbus - update to 8.2.0-33
qemu-audio-oss - update to 8.2.0-33
qemu-audio-pa - update to 8.2.0-33
qemu-audio-spice - update to 8.2.0-33
qemu-block-curl - update to 8.2.0-33
qemu-block-dmg - update to 8.2.0-33
qemu-block-gluster - update to 8.2.0-33
qemu-block-iscsi - update to 8.2.0-33
qemu-block-ssh - update to 8.2.0-33
qemu-char-baum - update to 8.2.0-33
qemu-char-spice - update to 8.2.0-33
qemu-common - update to 8.2.0-33
qemu-device-display-qxl - update to 8.2.0-33
qemu-device-display-virtio-gpu - update to 8.2.0-33
qemu-device-display-virtio-gpu-ccw - update to 8.2.0-33
qemu-device-display-virtio-gpu-pci - update to 8.2.0-33
qemu-device-display-virtio-vga - update to 8.2.0-33
qemu-device-display-virtio-vga-gl - update to 8.2.0-33
qemu-device-usb-host - update to 8.2.0-33
qemu-device-usb-redirect - update to 8.2.0-33

External References

Related Security Bulletins