Description
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
Published: 2024-10-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-47600 A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
History

Fri, 08 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Qemu
Qemu qemu
CPEs cpe:2.3:a:qemu:qemu:-:*:*:*:*:*:*:*
Vendors & Products Qemu
Qemu qemu

Mon, 21 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Oct 2024 14:45:00 +0000

Type Values Removed Values Added
Title QEMU: SCSI: lsi53c895a: use-after-free local privilege escalation vulnerability Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability
First Time appeared Redhat
Redhat advanced Virtualization
Redhat enterprise Linux
CPEs cpe:/a:redhat:advanced_virtualization:8::el8
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat advanced Virtualization
Redhat enterprise Linux
References

Sat, 19 Oct 2024 02:30:00 +0000

Type Values Removed Values Added
References

Sat, 12 Oct 2024 01:15:00 +0000

Type Values Removed Values Added
Description A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
Title QEMU: SCSI: lsi53c895a: use-after-free local privilege escalation vulnerability
Weaknesses CWE-416
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

threat_severity

Important


Subscriptions

Qemu Qemu
Redhat Advanced Virtualization Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2024-10-21T15:49:23.239Z

Reserved: 2024-07-04T19:12:32.075Z

Link: CVE-2024-6519

cve-icon Vulnrichment

Updated: 2024-10-21T15:49:19.478Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-21T15:15:03.727

Modified: 2025-08-08T16:13:16.730

Link: CVE-2024-6519

cve-icon Redhat

Severity : Important

Publid Date: 2024-10-10T00:00:00Z

Links: CVE-2024-6519 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses