Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-26354

Опубликовано: 16 мар. 2022
Источник: nvd
CVSS3: 3.2
CVSS2: 2.1
EPSS Низкий

Описание

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*
Версия до 6.2.0 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 1%
0.00011
Низкий

3.2 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-772
CWE-772

Связанные уязвимости

CVSS3: 3.2
ubuntu
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 2.5
redhat
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
msrc
около 1 года назад

Описание отсутствует

CVSS3: 3.2
debian
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, ...

CVSS3: 3.2
github
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

EPSS

Процентиль: 1%
0.00011
Низкий

3.2 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-772
CWE-772