CVE-2024-3447
Estado: ModificadaMedia (6)—
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
- Puntuación base: 6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.55%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-122
Referencias
- https://access.redhat.com/security/cve/CVE-2024-3447
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=58813
- https://bugzilla.redhat.com/show_bug.cgi?id=2274123
- https://patchew.org/QEMU/20240404085549.16987-1-philmd@linaro.org/
- https://lists.debian.org/debian-lts-announce/2025/04/msg00042.html
- https://security.netapp.com/advisory/ntap-20250425-0005/
- https://cert-portal.siemens.com/productcert/html/ssa-577017.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-3447",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-3447",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-14T18:53:42.574300Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "patrick@puiterwijk.org",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 4,
"exploitabilityScore": 1.5
}
]
},
"affected": [
{
"source": "patrick@puiterwijk.org",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "1.5.0",
"lessThan": "9.0.0",
"versionType": "semver"
}
],
"packageName": "qemu",
"collectionURL": "https://gitlab.com/qemu-project/qemu",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 6",
"packageName": "qemu-kvm",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 7",
"packageName": "qemu-kvm",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 7",
"packageName": "qemu-kvm-ma",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 8",
"packageName": "virt:rhel/qemu-kvm",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:advanced_virtualization:8::el8"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 8 Advanced Virtualization",
"packageName": "virt:av/qemu-kvm",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:9"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 9",
"packageName": "qemu-kvm",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
}
]
},
{
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"affectedData": [
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX MX5000",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX MX5000RE",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX RX1400",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX RX1500",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX RX1501",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX RX1510",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX RX1511",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX RX1512",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX RX1524",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX RX1536",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "RUGGEDCOM ROX RX5000",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V2.17.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-11-14T12:15:17.743",
"references": [
{
"url": "https://access.redhat.com/security/cve/CVE-2024-3447",
"tags": [
"Third Party Advisory"
],
"source": "patrick@puiterwijk.org"
},
{
"url": "https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=58813",
"tags": [
"Exploit",
"Issue Tracking"
],
"source": "patrick@puiterwijk.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2274123",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "patrick@puiterwijk.org"
},
{
"url": "https://patchew.org/QEMU/20240404085549.16987-1-philmd@linaro.org/",
"tags": [
"Broken Link"
],
"source": "patrick@puiterwijk.org"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00042.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20250425-0005/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-577017.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "patrick@puiterwijk.org",
"description": [
{
"lang": "en",
"value": "CWE-122"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition."
},
{
"lang": "es",
"value": "Se encontró un desbordamiento de búfer basado en montón en la emulación de dispositivo SDHCI de QEMU. El error se activa cuando tanto `s->data_count` como el tamaño de `s->fifo_buffer` se establecen en 0x200, lo que genera un acceso fuera de los límites. Un invitado malintencionado podría usar esta falla para bloquear el proceso QEMU en el host, lo que genera una condición de denegación de servicio."
}
],
"lastModified": "2026-06-17T07:44:17.620",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0EAD89F2-2AEA-4655-B072-E12C2AD69711",
"versionEndExcluding": "7.2.11"
},
{
"criteria": "cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59D5C13B-B7C8-4057-94E6-D5B29B0C745B",
"versionEndExcluding": "8.2.3",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:qemu:qemu:9.0.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53B020E1-1339-4E3B-8CC3-7108309DF2F1"
},
{
"criteria": "cpe:2.3:a:qemu:qemu:9.0.0:rc0:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E7620C7-95CD-4451-A485-69CF3752627B"
},
{
"criteria": "cpe:2.3:a:qemu:qemu:9.0.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8EBBE5A-0A6F-4F35-AA50-CA81B15F6BDC"
},
{
"criteria": "cpe:2.3:a:qemu:qemu:9.0.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45846E0D-C683-4DAF-AE17-32CD8EB283F3"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AFE5CAF-ACA7-4F82-BEC1-69562D75E66E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "patrick@puiterwijk.org"
}