Bugzilla – Bug 1215192
VUL-0: CVE-2023-42467: qemu,kvm: division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c
Last modified: 2023-11-30 07:58:19 UTC
CVE-2023-42467 QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately. Upstream commit: https://gitlab.com/thuth/qemu/-/commit/3f91104484e5bf55b56d7e1b039a4a5a17d0c1a7 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-42467 https://www.cve.org/CVERecord?id=CVE-2023-42467 https://gitlab.com/qemu-project/qemu/-/issues/1813