CVE-2023-3354
Publication date 11 July 2023
Last updated 9 June 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.
Read the notes from the security team
Why is this CVE low priority?
Limited to a denial of service in the VNC server component.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| qemu | 26.04 LTS resolute |
Not affected
|
| 25.10 questing |
Not affected
|
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Fixed 1:6.2+dfsg-2ubuntu6.16
|
|
| 20.04 LTS focal |
Fixed 1:4.2-3ubuntu6.28
|
|
| 18.04 LTS bionic |
Fixed 1:2.11+dfsg-1ubuntu7.42+esm5
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.5 · High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Related Ubuntu Security Notices (USN)
- USN-6567-1
- QEMU vulnerabilities
- 8 January 2024
- USN-8412-1
- QEMU vulnerabilities
- 9 June 2026