We found results for “”
CVE-2023-3180
Date: August 3, 2023
A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of "src_len" and "dst_len" in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.
Language: C
Severity Score
Related Resources (8)
Severity Score
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | LOCAL |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


