CVE-2024-3447: Netapp Hci Compute Node

Medium severity, CVSS 6.0. EPSS: 0.6% chance of exploitation in the next 30 days.

A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

Affected products

  • Netapp Hci Compute Node: affected versions not specified
  • Qemu Qemu: before 7.2.11 (fixed in 7.2.11); from 8.0.0, before 8.2.3 (fixed in 8.2.3); version 9.0.0 only

Published 2024-11-14. Last modified 2026-06-17.