CVE-2023-3180: Debian Linux

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 38 only
  • Qemu Qemu: before 8.1.0 (fixed in 8.1.0); version 8.1.0 only

Published 2023-08-03. Last modified 2026-06-17.