CVE-2024-3447
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 29
Summary
CVE-2024-3447 is a newly discovered vulnerability in the SDHCI device emulation of QEMU. This issue involves a heap-based buffer overflow that is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200. Consequently, an out-of-bound access occurs, creating an opportunity for malicious guests to exploit this flaw and cause the QEMU process on the host to crash. The result is a denial of service condition.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.