The vulnerability exists due to a boundary error in the SDHCI device emulation. A malicious guest can set both "s->data_count" and the size of "s->fifo_buffer" to the value of "0x200" to trigger an out-of-bound memory access and perform a denial of service (DoS) attack.
This Cyber News was published on www.tenable.com. Publication date: Fri, 07 Jun 2024 15:11:03 +0000