Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-26354

Опубликовано: 28 фев. 2022
Источник: redhat
CVSS3: 2.5

Описание

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results.

Отчет

This issue affects the versions of qemu-kvm as shipped with Red Hat Enterprise Linux 8 and Red Hat Enterprise Linux 8 Advanced Virtualization. A future update may address this flaw.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvm-maOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmAffected
Red Hat OpenStack Platform 13 (Queens)qemu-kvm-rhevOut of support scope
Advanced Virtualization for RHEL 8.4.0.EUSvirtFixedRHSA-2022:500213.06.2022
Advanced Virtualization for RHEL 8.4.0.EUSvirt-develFixedRHSA-2022:500213.06.2022
Red Hat Enterprise Linux 8virt-develFixedRHSA-2022:582102.08.2022
Red Hat Enterprise Linux 8virtFixedRHSA-2022:582102.08.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2063257QEMU: vhost-vsock: missing virtqueue detach on error can lead to memory leak

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 3.2
ubuntu
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
nvd
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
msrc
около 1 года назад

Описание отсутствует

CVSS3: 3.2
debian
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, ...

CVSS3: 3.2
github
больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

2.5 Low

CVSS3