{"schema_version":"1.9.0","id":"CVE-2024-3447","published":"2024-11-14T12:10:36.880Z","modified":"2026-08-12T03:51:33.071424170Z","related":["SUSE-SU-2024:1394-1","SUSE-SU-2024:1438-1","SUSE-SU-2024:1438-2","SUSE-SU-2024:3229-1","SUSE-SU-2025:0692-1","SUSE-SU-2025:20011-1","openSUSE-SU-2024:13876-1"],"summary":"Qemu: sdhci: heap buffer overflow in sdhci_write_dataport()","details":"A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of  `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qemu/qemu","events":[{"introduced":"0"},{"fixed":"c6fe0f315cfac9739c8d57ffa05c9c22d7ebd2cb"},{"introduced":"c1eb2ddf0f8075faddc5f7c3d39feae3e8e9d6b4"},{"fixed":"8216663a5c88968a62f67e4aa80807167efceb8d"},{"introduced":"c25df57ae8f9fe1c72eee2dab37d76d904ac382e"},{"last_affected":"e5c6528dce86d7a9ada7ecf02fcb7b8560955131"}],"database_specific":{"cpe":["cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*","cpe:2.3:a:qemu:qemu:9.0.0:-:*:*:*:*:*:*","cpe:2.3:a:qemu:qemu:9.0.0:rc0:*:*:*:*:*:*","cpe:2.3:a:qemu:qemu:9.0.0:rc1:*:*:*:*:*:*","cpe:2.3:a:qemu:qemu:9.0.0:rc2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"7.2.11"},{"introduced":"8.0.0"},{"fixed":"8.2.3"},{"introduced":"9.0.0-NA"},{"last_affected":"9.0.0-NA"},{"introduced":"9.0.0-rc0"},{"last_affected":"9.0.0-rc0"},{"introduced":"9.0.0-rc1"},{"last_affected":"9.0.0-rc1"},{"introduced":"9.0.0-rc2"},{"last_affected":"9.0.0-rc2"}],"source":["CPE_RANGE","CPE_STRING"]}},{"type":"GIT","repo":"https://gitlab.com/qemu-project/qemu","events":[{"introduced":"371386fb60961e0afc02f03c817dff79633e323e"},{"fixed":"c25df57ae8f9fe1c72eee2dab37d76d904ac382e"}],"database_specific":{"extracted_events":[{"introduced":"1.5.0"},{"fixed":"9.0.0"}],"source":"AFFECTED_FIELD"}}],"versions":["9.0.0-NA","9.0.0-rc0","9.0.0-rc1","9.0.0-rc2","v9.0.0-rc2","v9.0.0-rc1","v9.0.0-rc0","v7.2.10","v8.2.2","v7.2.9","v8.2.1","v7.2.8","v8.2.0","v8.2.0-rc4","v8.2.0-rc3","v8.2.0-rc2","v8.2.0-rc1","v7.2.7","v8.2.0-rc0","v7.2.6","v7.2.5","v8.1.0","v8.1.0-rc4","v8.1.0-rc3","v8.1.0-rc2","v8.1.0-rc1","v8.1.0-rc0","v7.2.4","v7.2.3","v8.0.0","v7.2.2","staging-mjt-test","v7.2.1","v7.2.0","v7.2.0-rc4","v7.2.0-rc3","v7.2.0-rc2","v7.2.0-rc1","v7.2.0-rc0","v7.1.0","v7.1.0-rc4","v7.1.0-rc3","v7.1.0-rc2","v7.1.0-rc1","v7.1.0-rc0","v7.0.0","v7.0.0-rc4","v7.0.0-rc3","v7.0.0-rc2","v7.0.0-rc1","v7.0.0-rc0","v6.2.0","v6.2.0-rc4","v6.1.0","v6.2.0-rc3","v6.2.0-rc1","v6.2.0-rc0","v6.0.0","v6.1.0-rc4","v6.1.0-rc3","v6.1.0-rc2","v6.1.0-rc1","v6.1.0-rc0","v6.0.0-rc5","v6.0.0-rc4","v6.0.0-rc3","v6.0.0-rc2","v6.0.0-rc1","v6.0.0-rc0","v5.2.0","v5.2.0-rc4","v5.2.0-rc3","v5.2.0-rc2","v5.2.0-rc1","v5.2.0-rc0","v5.0.0","v5.1.0","v5.1.0-rc3","v5.1.0-rc2","v5.1.0-rc1","v5.1.0-rc0","v4.2.0","v5.0.0-rc4","v5.0.0-rc3","v5.0.0-rc2","v5.0.0-rc1","v5.0.0-rc0","v4.2.0-rc5","v4.2.0-rc4","v4.2.0-rc3","v4.2.0-rc2","v4.2.0-rc1","v4.2.0-rc0","v4.1.0","v4.0.0","v4.1.0-rc5","v4.1.0-rc4","v4.1.0-rc3","v4.1.0-rc2","v4.1.0-rc1","v4.1.0-rc0","v4.0.0-rc4","v4.0.0-rc3","v4.0.0-rc2","v4.0.0-rc1","v3.1.0","v4.0.0-rc0","v3.0.0","v3.1.0-rc5","v3.1.0-rc4","v3.1.0-rc3","v3.1.0-rc2","v3.1.0-rc1","v3.1.0-rc0","v3.0.0-rc4","v3.0.0-rc3","v3.0.0-rc2","v3.0.0-rc1","v3.0.0-rc0","v2.12.0","v2.12.0-rc4","v2.12.0-rc3","v2.12.0-rc2","v2.12.0-rc1","v2.12.0-rc0","v2.11.0","v2.11.0-rc5","v2.11.0-rc4","v2.11.0-rc3","v2.11.0-rc2","v2.11.0-rc1","v2.11.0-rc0","v2.10.0","v2.10.0-rc4","v2.10.0-rc3","v2.10.0-rc2","v2.10.0-rc1","v2.9.0","v2.10.0-rc0","v2.9.0-rc5","v2.9.0-rc4","v2.9.0-rc3","v2.9.0-rc2","v2.9.0-rc1","v2.8.0","v2.9.0-rc0","v2.8.0-rc4","v2.8.0-rc3","v2.8.0-rc2","v2.8.0-rc1","v2.8.0-rc0","v2.7.0","v2.7.0-rc5","v2.7.0-rc4","v2.7.0-rc3","v2.7.0-rc2","v2.6.0","v2.7.0-rc1","v2.7.0-rc0","v2.6.0-rc5","v2.6.0-rc4","v2.6.0-rc3","v2.6.0-rc2","v2.6.0-rc1","v2.6.0-rc0","v2.5.0","v2.5.0-rc4","v2.5.0-rc3","v2.5.0-rc2","v2.5.0-rc1","v2.5.0-rc0","v2.4.0","v2.4.0-rc4","v2.4.0-rc3","v2.3.0","v2.4.0-rc2","v2.4.0-rc1","v2.4.0-rc0","v2.3.0-rc4","v2.3.0-rc3","v2.3.0-rc2","v2.3.0-rc1","v2.3.0-rc0","v2.2.0","v2.2.0-rc3","v2.2.0-rc5","v2.2.0-rc4","v2.2.0-rc2","v2.2.0-rc1","v2.2.0-rc0","v2.1.0","v2.1.0-rc5","v2.1.0-rc4","v2.1.0-rc2","v2.1.0-rc3","v2.0.0","v2.1.0-rc1","v2.1.0-rc0","v2.0.0-rc3","v2.0.0-rc2","v2.0.0-rc1","v2.0.0-rc0","v1.7.0","v1.7.0-rc2","v1.7.0-rc1","v1.7.0-rc0","v1.6.0","v1.6.0-rc3","v1.6.0-rc2","v1.6.0-rc1","v1.6.0-rc0","v1.5.0","v1.5.0-rc3","v1.5.0-rc2","v1.5.0-rc1","v1.5.0-rc0","v1.4.0","v1.4.0-rc2","v1.4.0-rc1","v1.4.0-rc0","v1.3.0","v1.3.0-rc2","v1.3.0-rc1","v1.3.0-rc0","v1.2.0","v1.2.0-rc3","v1.2.0-rc2","v1.2.0-rc1","v1.2.0-rc0","v1.1.0","v1.1.0-rc4","v1.1.0-rc3","v1.1.0-rc2","v1.1-rc2","v1.1-rc1","v1.1-rc0","v1.0","v1.0-rc4","v1.0-rc3","v1.0-rc2","v1.0-rc1","v1.0-rc0","v0.14.0-rc0","v0.13.0-rc0","v0.12.0-rc0","v0.11.0-rc0","v0.5.0","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4.0","v0.3.0","v0.2.0","v0.1.6","v0.1.5","v0.1.4","v0.1.3","v0.1.1","v0.1.0","v9.0.0-rc4","v9.0.0-rc3","v8.0.0-rc4","v8.0.0-rc3","v8.0.0-rc2","v8.0.0-rc1","v8.0.0-rc0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3447.json"}}],"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=58813"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-577017.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00042.html"},{"type":"WEB","url":"https://patchew.org/QEMU/20240404085549.16987-1-philmd@linaro.org/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2024-3447"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/3xxx/CVE-2024-3447.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3447"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250425-0005/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2274123"},{"type":"PACKAGE","url":"https://gitlab.com/qemu-project/qemu"}],"database_specific":{"cna_assigner":"fedora","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/3xxx/CVE-2024-3447.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H"}]}