CVE-2024-3446: Red Hat Enterprise Linux 6

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.

Affected products

  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 8100020240905091210.489197e6 (fixed in 8100020240905091210.489197e6)
  • Red Hat Red Hat Enterprise Linux 8 Advanced Virtualization
  • Red Hat Red Hat Enterprise Linux 9

Published 2024-04-09. Last modified 2026-06-17.