HomeDefectsLIN1024-15766
Fixed

LIN1024-15766 : Security Advisory - qemu - CVE-2023-6683

Created: Mar 19, 2026    Updated: Mar 25, 2026
Resolved Date: Mar 19, 2026
Found In Version: 10.24.33.16
Fix Version: 10.24.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service.

CVEs