In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade Oracle:8 libvirt-devel to version 0:5.7.0-44.module+el8.10.0+90415+56803fd5 or higher.
This issue was patched in ELSA-2024-12791.
Note: Versions mentioned in the description apply only to the upstream libvirt-devel package and not the libvirt-devel package as distributed by Oracle.
See How to fix? for Oracle:8 relevant fixed versions and status.
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both s->data_count and the size of s->fifo_buffer are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.