CVE-2024-7409

Executive Summary

CVE-2024-7409 exposes a denial‑of‑service flaw in QEMU’s Network Block Device (NBD) server. Improper synchronization during socket closure allows an attacker to keep a client socket open while the server is taken offline, causing the server to crash or become unresponsive. The vulnerability can be triggered remotely by any client that connects to the NBD service, potentially disrupting virtual machine storage access. No public exploits are known, but updating QEMU to patched versions or disabling NBD mitigates the risk.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2024-08-05T14:15:35.813 - Last Modified: 2026-08-31T18:17:08.330

Original Description: A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

"What lies behind us and what lies before us are tiny matters compared to what lies within us."

— Walt Emerson
Source: NVD