CVE-2024-24474

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
20/02/2024
Last modified:
25/06/2025

Description

QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the length of the available FIFO data. This occurs in esp_do_nodma in hw/scsi/esp.c because of an underflow of async_len.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qemu:qemu:*:-:*:*:*:*:*:* 8.2.0 (excluding)