{"schema_version":"1.9.0","id":"CVE-2024-8354","published":"2024-09-19T10:45:06.191Z","modified":"2026-08-12T03:51:40.764257814Z","related":["CGA-gfjg-cf9q-j562","SUSE-SU-2024:3744-1","SUSE-SU-2024:3948-1","SUSE-SU-2024:4094-1","SUSE-SU-2024:4304-1","SUSE-SU-2025:20076-1"],"summary":"Qemu-kvm: usb: assertion failure in usb_ep_get()","details":"A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qemu/qemu","events":[{"introduced":"609d7596524ab204ccd71ef42c9eee4c7c338ea4"},{"last_affected":"c25df57ae8f9fe1c72eee2dab37d76d904ac382e"}],"database_specific":{"cpe":["cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*","cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.0"},{"last_affected":"6.0"},{"introduced":"7.0"},{"last_affected":"7.0"},{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING"}}],"versions":["6.0","7.0","8.0","9.0","v9.0.0","v9.0.0-rc4","v9.0.0-rc3","v9.0.0-rc2","v9.0.0-rc1","v9.0.0-rc0","v8.2.0","v8.2.0-rc4","v8.2.0-rc3","v8.2.0-rc2","v8.2.0-rc1","v8.2.0-rc0","v8.1.0","v8.1.0-rc4","v8.1.0-rc3","v8.1.0-rc2","v8.1.0-rc1","v8.1.0-rc0","v8.0.0","v8.0.0-rc4","v8.0.0-rc3","v8.0.0-rc2","v7.2.0","v8.0.0-rc1","v8.0.0-rc0","v7.2.0-rc4","v7.2.0-rc3","v7.2.0-rc2","v7.2.0-rc1","v7.2.0-rc0","v7.1.0","v7.1.0-rc4","v7.1.0-rc3","v7.1.0-rc2","v7.1.0-rc1","v7.1.0-rc0","v7.0.0","v7.0.0-rc4","v7.0.0-rc3","v7.0.0-rc2","v7.0.0-rc1","v7.0.0-rc0","v6.2.0","v6.2.0-rc4","v6.1.0","v6.2.0-rc3","v6.2.0-rc1","v6.2.0-rc0","v6.0.0","v6.1.0-rc4","v6.1.0-rc3","v6.1.0-rc2","v6.1.0-rc1","v6.1.0-rc0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8354.json"}}],"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2024-8354"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8354.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8354"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241011-0008/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2313497"},{"type":"PACKAGE","url":"https://gitlab.com/qemu-project/qemu"}],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8354.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}