A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
History

Mon, 21 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Oct 2024 14:45:00 +0000

Type Values Removed Values Added
Title QEMU: SCSI: lsi53c895a: use-after-free local privilege escalation vulnerability Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability
First Time appeared Redhat
Redhat advanced Virtualization
Redhat enterprise Linux
CPEs cpe:/a:redhat:advanced_virtualization:8::el8
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat advanced Virtualization
Redhat enterprise Linux
References

Sat, 19 Oct 2024 02:30:00 +0000

Type Values Removed Values Added
References

Sat, 12 Oct 2024 01:15:00 +0000

Type Values Removed Values Added
Description A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
Title QEMU: SCSI: lsi53c895a: use-after-free local privilege escalation vulnerability
Weaknesses CWE-416
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2024-10-21T14:36:40.115Z

Updated: 2024-10-21T15:49:23.239Z

Reserved: 2024-07-04T19:12:32.075Z

Link: CVE-2024-6519

cve-icon Vulnrichment

Updated: 2024-10-21T15:49:19.478Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-21T15:15:03.727

Modified: 2024-10-21T17:09:45.417

Link: CVE-2024-6519

cve-icon Redhat

Severity : Important

Publid Date: 2024-10-10T00:00:00Z

Links: CVE-2024-6519 - Bugzilla