A flaw was found in the QEMU virtual crypto device while...
Moderate severity
Unreviewed
Published
Aug 3, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Aug 3, 2023
Published to the GitHub Advisory Database
Aug 3, 2023
Last updated
Apr 4, 2024
A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of
src_len
anddst_len
in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.References