Loading HuntDB...

GHSA-jr85-6g96-46pc

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.

Related CVEs

Key Information

GHSA ID
GHSA-jr85-6g96-46pc
Published
August 27, 2022 12:00 AM
Last Modified
September 2, 2022 12:01 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 31, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.