A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

Subscriptions

Vendors Products
Hci Compute Node Subscribe
Advanced Virtualization Subscribe
Enterprise Linux Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4144-1 qemu security update
EUVD EUVD EUVD-2024-32034 A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
Ubuntu USN Ubuntu USN USN-7744-1 QEMU vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 03 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
References

Tue, 05 Aug 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Netapp
Netapp hci Compute Node
Qemu
Qemu qemu
CPEs cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*
cpe:2.3:a:qemu:qemu:9.0.0:-:*:*:*:*:*:*
cpe:2.3:a:qemu:qemu:9.0.0:rc0:*:*:*:*:*:*
cpe:2.3:a:qemu:qemu:9.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:qemu:qemu:9.0.0:rc2:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
Vendors & Products Netapp
Netapp hci Compute Node
Qemu
Qemu qemu

Fri, 25 Apr 2025 23:45:00 +0000

Type Values Removed Values Added
References

Thu, 14 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Nov 2024 12:15:00 +0000

Type Values Removed Values Added
Title QEMU: sdhci: heap buffer overflow in sdhci_write_dataport() Qemu: sdhci: heap buffer overflow in sdhci_write_dataport()
First Time appeared Redhat
Redhat advanced Virtualization
Redhat enterprise Linux
CPEs cpe:/a:redhat:advanced_virtualization:8::el8
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat advanced Virtualization
Redhat enterprise Linux
References

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2025-11-03T19:29:52.539Z

Reserved: 2024-04-08T07:52:52.103Z

Link: CVE-2024-3447

cve-icon Vulnrichment

Updated: 2025-11-03T19:29:52.539Z

cve-icon NVD

Status : Modified

Published: 2024-11-14T12:15:17.743

Modified: 2025-11-03T20:16:26.963

Link: CVE-2024-3447

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-04-04T00:00:00Z

Links: CVE-2024-3447 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses