Database/Kernel, userspace & hypervisor
QEMU (virtio): DMA reentrancy leads to double free across virtio devices - guest-to-host code execution in QEMU
CVE-2024-3446Kernel, userspace & hypervisorcurated
Impact
DMA reentrancy leads to double free across virtio devices - guest-to-host code execution in QEMU
Who can reach it
Tenant VM guest
What to do
QEMU update + VM restart or live-migration to patched hosts. GPU-passthrough VMs cannot be live-migrated, so this is a scheduled tenant-visible drain
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.