CVE-2024-3446

Source
https://cve.org/CVERecord?id=CVE-2024-3446
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-3446.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-3446
Downstream
Related
Withdrawn
2026-01-27T04:20:10.742691Z
Published
2024-04-09T20:15:10Z
Modified
2026-01-27T04:20:10.742691Z
Summary
[none]
Details

A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the memreentrancyguard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.

References

Affected packages