March 23, 2023, 8:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a huge number of page tables to be used as a ring of descriptors for CQ and async events, potentially leading to an out-of-bounds read and crash of QEMU.

async crash cve device driver events fedora flaw out-of-bounds qemu ring tables vmware

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Network Security Engineer

@ Ørsted | Kuala Lumpur, MY

Senior Director of Foundation Relations, Johns Hopkins University & Medicine

@ Johns Hopkins University | Baltimore, MD, United States, 21209

Global Cybersecurity Head

@ CMA CGM | Marseille, FR

Cyber Security Analyst

@ QinetiQ US | Reston, VA, United States