Guest-triggered host crash via short fragmented SCTP packet
Published Apr 10, 2024 · Updated Nov 8, 2025
Reachable assertion in QEMU 8.2.92 allows guest OS users to crash the virtualization process via a short fragmented SCTP packet. In hw/net/net_tx_pkt.c, update_sctp_checksum processes a fragment shorter than the SCTP checksum field and passes it to iov_from_buf_full, which aborts when its offset cannot be satisfied. A guest able to submit transmit descriptors through an emulated igb network device can terminate its QEMU process and interrupt the hosted virtual machine.
Summary
What happened
Reachable assertion in QEMU 8.2.92 allows guest OS users to crash the virtualization process via a short fragmented SCTP packet. In hw/net/net_tx_pkt.c, update_sctp_checksum processes a fragment shorter than the SCTP checksum field and passes it to iov_from_buf_full, which aborts when its offset cannot be satisfied. A guest able to submit transmit descriptors through an emulated igb network device can terminate its QEMU process and interrupt the hosted virtual machine.
The record
- CVE
- CVE-2024-3567
- Published
- Apr 10, 2024
- Updated
- Nov 8, 2025
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 9
- Classifications
- CWE-617, T1499
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Apr 10, 2024CVE publishedPublication date reported by the CVE source.
- Nov 8, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Affected versions are unavailable in this record. Check the vendor advisory for version and patch details.
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- QEMU qtest short-fragment crash reproducerproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo