CVE-2023-3019
Moderate
Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
Exploit probability
0.3%
Published
July 24, 2023
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
244 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2023-3019
View original source
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
05 / REFERENCES
Further evidence
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2024:0135
- https://access.redhat.com/errata/RHSA-2024:0404
- https://access.redhat.com/errata/RHSA-2024:0569
- https://access.redhat.com/errata/RHSA-2024:2135
- https://access.redhat.com/security/cve/CVE-2023-3019
- https://bugzilla.redhat.com/show_bug.cgi?id=2222351
- https://cert-portal.siemens.com/productcert/html/ssa-577017.html
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3019.json
- https://lists.debian.org/debian-lts-announce/2025/04/msg00042.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-3019
- https://security.netapp.com/advisory/ntap-20230831-0005/