CVE-2023-3180 | QEMU Virtual Crypto Device virtio-crypto.c virtio_crypto_sym_op_helper src_len/dst_len heap-based overflow (Nessus ID 209571)
A vulnerability has been found in QEMU and classified as critical. This vulnerability affects the function virtio_crypto_sym_op_helper of the file hw/virtio/virtio-crypto.c of the component Virtual Crypto Device. The manipulation of the argument src_len/dst_len leads to heap-based buffer overflow.
This vulnerability was named CVE-2023-3180. Access to the local network is required for this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.