CVE-2024-4693 is a medium-severity flaw in QEMU's Virtio PCI Bindings (hw/virtio/virtio-pci.c) that allows a malicious guest to crash the host QEMU process. This vulnerability stems from an improper release and use of the irqfd for vector 0 during the boot process, which can be triggered via vhost_net_stop(). The attack requires local access and low privileges (CVSS: 5.5, AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), leading to a denial of service. There is currently no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 Advanced Virtualization | Range not provided by sourceCNA affecteddefault unknown | |
| Red Hat | Red Hat Enterprise Linux 6 | Range not provided by sourceCNA affecteddefault unknown | |
| Red Hat | Red Hat Enterprise Linux 7 | Range not provided by sourceCNA affecteddefault unknown | |
| Red Hat | Red Hat Enterprise Linux 9 | All Versions ImpactedCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.