The vendor explicitly states that these products are not affected by this CVE.
- qemu-guest-agent as a component of Red Hat Enterprise Linux 10
- qemu-img as a component of Red Hat Enterprise Linux 10
- qemu-kvm as a component of Red Hat Enterprise Linux 10
- qemu-kvm-audio-pa as a component of Red Hat Enterprise Linux 10
- qemu-kvm-block-blkio as a component of Red Hat Enterprise Linux 10
- qemu-kvm-block-curl as a component of Red Hat Enterprise Linux 10
- qemu-kvm-block-rbd as a component of Red Hat Enterprise Linux 10
- qemu-kvm-common as a component of Red Hat Enterprise Linux 10
- qemu-kvm-core as a component of Red Hat Enterprise Linux 10
- qemu-kvm-device-display-virtio-gpu as a component of Red Hat Enterprise Linux 10
- qemu-kvm-device-display-virtio-gpu-ccw as a component of Red Hat Enterprise Linux 10
- qemu-kvm-device-display-virtio-gpu-pci as a component of Red Hat Enterprise Linux 10
- Summary
- An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.
- Remediation
- No remediation text is recorded.
