Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-4172

Опубликовано: 29 нояб. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

РелизСтатусПримечание
bionic

not-affected

code not present
devel

not-affected

1:7.2+dfsg-5ubuntu2
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

1:4.2-3ubuntu6.24
esm-infra/xenial

not-affected

code not present
focal

not-affected

1:4.2-3ubuntu6.24
jammy

not-affected

1:6.2+dfsg-2ubuntu6.6
kinetic

released

1:7.0+dfsg-7ubuntu2.6
lunar

not-affected

1:7.2+dfsg-5ubuntu2

Показывать по

EPSS

Процентиль: 5%
0.00023
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6
redhat
больше 2 лет назад

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

CVSS3: 6.5
nvd
больше 2 лет назад

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

CVSS3: 6.5
debian
больше 2 лет назад

An integer overflow and buffer overflow issues were found in the ACPI ...

CVSS3: 6.5
github
больше 2 лет назад

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость функций read_erst_record() и write_erst_record() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 5%
0.00023
Низкий

6.5 Medium

CVSS3