CVE-2023-42467

Public on 2023-09-11
Modified on 2023-09-12
Description
QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately.
Severity
Medium severity
Medium
CVSS v3 Base Score
4.4
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 2 - Core qemu Not Affected
HAQM Linux 1 qemu-kvm Not Affected
HAQM Linux 2 - Core qemu-kvm Not Affected

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H