Qemu-kvm: usb: assertion failure in usb_ep_get()
A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.
02 / AFFECTED SOFTWARE
Affected packages
58 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.
05 / REFERENCES
Further evidence
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/security/cve/CVE-2024-8354
- https://bugzilla.redhat.com/show_bug.cgi?id=2313497
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8354.json
- https://gitlab.com/qemu-project/qemu
- https://nvd.nist.gov/vuln/detail/CVE-2024-8354
- https://security.netapp.com/advisory/ntap-20241011-0008/