Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-26354

Опубликовано: 16 мар. 2022
Источник: debian
EPSS Низкий

Описание

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:7.0+dfsg-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2063257

  • https://gitlab.com/qemu-project/qemu/-/commit/8d1b247f3748ac4078524130c6d7ae42b6140aaf

  • vulnerable code in buster in vhost_vsock_send_transport_reset

EPSS

Процентиль: 1%
0.0001
Низкий

Связанные уязвимости

CVSS3: 3.2
ubuntu
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 2.5
redhat
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
nvd
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 3.2
github
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

EPSS

Процентиль: 1%
0.0001
Низкий