CVE-2023-3019

Public on 2023-07-13
Modified on 2025-10-22
Description
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.

Amazon Linux will not be providing a fix for CVE-2023-3019 at this time after considering the tradeoff between the stability of Amazon Linux and the impact of CVE-2023-3019. We recommend that customers ensure only trusted clients can access privileged QEMU guest agents.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.0
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 kernel Not Affected
Amazon Linux 2 - Core qemu-kvm No Fix Planned

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H