CVE-2024-7409
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during sock
CVSS
7.5
Alto
EPSS
1.0%
p61
KEV
—
Exploit Today
18
0-100
Publicado: 5 ago 2024 · Última mod.: 31 ago 2026 · CWE-662
1.0%EPSS · 30 días1.0%
2026-08-022026-08-31
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:10518
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:10528
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:10813
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:6811
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:6818
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:6964
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:7408
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8991
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:9136
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:9620
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:9912
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2024-7409
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2302487
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/09/msg00011.html
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20250502-0008/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-532778.8 ALT1.2%
——0In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation
walk_s1() and kvm_walk_nested_s2() expect to be called while holding
kvm->srcu to guard against memslot changes. While this is generally
the case, __kvm_at_s12() and __kvm_find_s1_desc_level() call into the
respective walkers without taking kvm->srcu.
Fix by acquiring kvm->srcu prior to the table walk in both instances.48dCVE-2026-398655.9 MED51.8%
——16Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSession() method in lib/adapters/http.js. The session cleanup logic contains a control flow error when removing sessions from the sessions array. This vulnerability is fixed in 1.13.2.38d