CVE-2024-6505

Aliases:DEBIAN-CVE-2024-6505CGA-2479-rhrp-m8qcCGA-28gc-4fp4-q9g7CGA-2vxc-w682-58j3CGA-2xg3-7gp8-8xh2CGA-378v-f39f-2736CGA-3fgx-7gx7-grfxCGA-43px-x34f-xjpwCGA-44mx-83f5-jjc2CGA-5vfh-wmpq-4vmjCGA-6fq5-g3x8-gfxgCGA-7w5x-5x9p-vc7vCGA-8h2c-vjj7-5gj7CGA-8xx7-4g45-r3hpCGA-cw4f-mfq8-5w4rCGA-f4gp-ww65-6mv2CGA-g49w-9973-2xr5CGA-gjmf-whwr-p542CGA-gjwv-wpjh-cjqqCGA-gxmg-384f-cpf9CGA-h476-m278-4qprCGA-hpc7-88c8-gwpwCGA-j2r2-8965-rgjjCGA-j3pp-3hj8-3vjmCGA-m5hp-65mg-69rwCGA-q8j3-cvvg-mr84CGA-v2qv-fg9c-77m9CGA-vccg-p9cm-x9w9CGA-x8qq-2vr9-pmh4
Modified
Published: 05 Jul 2024, 13:51
Last modified:08 Nov 2025, 07:13

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.8 MEDIUM
v3.1 (cve.org)
EPSS Score
0.66% LOW
1% probability +0.57%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Jul 2024, 13:51
Published
Vulnerability first disclosed
08 Nov 2025, 07:13
Last Modified
Vulnerability information updated

Description

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host.

CVSS Metrics

  • v3.1MEDIUMScore: 6.8CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.66% Percentile: 50%

Techniques & Countermeasures

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • chainguardqemu

    < 11.0.1-r0

  • chainguardqemu-block-iscsi

    < 11.0.1-r0

  • chainguardqemu-block-rbd

    < 11.0.1-r0

  • chainguardqemu-edk2-aarch64

    < 11.0.1-r0

  • chainguardqemu-edk2-x86_64

    < 11.0.1-r0

  • chainguardqemu-ipxe

    < 11.0.1-r0

  • chainguardqemu-modules

    < 11.0.1-r0

  • chainguardqemu-modules-spice

    < 11.0.1-r0

  • chainguardqemu-modules-usb-host

    < 11.0.1-r0

  • chainguardqemu-system-aarch64

    < 11.0.1-r0

  • chainguardqemu-system-x86_64

    < 11.0.1-r0

  • chainguardqemu-user

    < 11.0.1-r0

  • chainguardqemu-user-binfmt

    < 11.0.1-r0

  • chainguardqemu-utils

    < 11.0.1-r0

  • wolfiqemu

    < 11.0.1-r0

  • wolfiqemu-block-iscsi

    < 11.0.1-r0

  • wolfiqemu-block-rbd

    < 11.0.1-r0

  • wolfiqemu-edk2-aarch64

    < 11.0.1-r0

  • wolfiqemu-edk2-x86_64

    < 11.0.1-r0

  • wolfiqemu-ipxe

    < 11.0.1-r0

  • wolfiqemu-modules

    < 11.0.1-r0

  • wolfiqemu-modules-spice

    < 11.0.1-r0

  • wolfiqemu-modules-usb-host

    < 11.0.1-r0

  • wolfiqemu-system-aarch64

    < 11.0.1-r0

  • wolfiqemu-system-x86_64

    < 11.0.1-r0

  • wolfiqemu-user

    < 11.0.1-r0

  • wolfiqemu-user-binfmt

    < 11.0.1-r0

  • wolfiqemu-utils

    < 11.0.1-r0

  • debianqemu

    all | < 1:7.2+dfsg-7+deb12u8 | < 1:9.0.2+ds-3 | < 1:9.0.2+ds-3

  • qemuqemu

    na

  • redhatenterprise_linux

    8.0 | 9.0

References (8)