An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://lore.kernel.org/all/20240213055345-mutt-send-email-mst%40kernel.org/ | broken link |
https://security.netapp.com/advisory/ntap-20240419-0010/ | third party advisory |