CVE-2023-0330
NixOS vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2023-0330) was discovered in the lsi53c895a device affecting QEMU. The vulnerability was reported on January 11, 2023, and involves a DMA-MMIO reentrancy problem that could lead to memory corruption issues. The vulnerability affects the latest version of QEMU at the time of discovery (NVD, Debian Security).

Technical details

The vulnerability stems from a DMA-MMIO reentrancy problem in the lsi53c895a device implementation. The issue occurs when DMA writes are repeatedly triggered without proper address limitations, leading to reentrancy issues. The vulnerability cannot be resolved by simply modifying the 'attrs' flag in the pcidmawrite() function within lsimemwrite(). This can result in memory corruption bugs such as stack overflow or use-after-free conditions (Red Hat Bugzilla).

Impact

The vulnerability could allow a privileged local user to crash the QEMU process on the host system through memory corruption, specifically through stack overflow or use-after-free conditions. This could potentially lead to denial of service in virtualized environments (Red Hat Bugzilla).

Mitigation and workarounds

The issue was addressed through a patch that restricts the DMA engine to memory regions. The fix was implemented in various distribution updates, including Debian 10 (Buster) version 1:3.1+dfsg-8+deb10u11. The upstream fix was merged into QEMU through commit b987718bbb1d0eabf95499b976212dd5f0120d75 (Debian LTS, QEMU Patch).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12819HIGH8.1
  • NixOSNixOS
  • pgbouncer
NoYesDec 03, 2025
CVE-2025-20777MEDIUM6.7
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-65105MEDIUM5.3
  • NixOSNixOS
  • apptainer
NoYesDec 02, 2025
CVE-2025-20789MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-20788MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management