CVE-2023-42467: Qemu
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately.
Affected products
- Qemu Qemu: up to and including 8.0.0
Published 2023-09-11. Last modified 2026-06-17.