Логотип exploitDog
bind:"CVE-2022-26353" OR bind:"CVE-2021-3748" OR bind:"CVE-2022-26354" OR bind:"CVE-2022-0897"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-26353" OR bind:"CVE-2021-3748" OR bind:"CVE-2022-26354" OR bind:"CVE-2022-0897"

Количество 65

Количество 65

msrc логотип

CVE-2021-3748

почти 3 года назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-3748

почти 4 года назад

A use-after-free vulnerability was found in the virtio-net device of Q ...

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-9869

около 3 лет назад

ELSA-2022-9869: qemu-kvm security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9862

около 3 лет назад

ELSA-2022-9862: kvm_utils2 security update (IMPORTANT)

EPSS: Низкий
github логотип

GHSA-4f87-mww8-gm8x

почти 4 года назад

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2022-00753

больше 4 лет назад

Уязвимость реализации функции virtio_net_receive_rcu (hw/net/virtio-net.c) эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3605-1

около 4 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3604-1

около 4 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1461-1

около 4 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3653-1

около 4 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3605-1

около 4 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3604-1

около 4 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3519-1

около 4 лет назад

Security update for qemu

EPSS: Низкий
ubuntu логотип

CVE-2022-0897

почти 4 года назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-0897

почти 4 года назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2022-0897

почти 4 года назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0897

почти 4 года назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjLis ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-26354

почти 4 года назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
EPSS: Низкий
redhat логотип

CVE-2022-26354

почти 4 года назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 2.5
EPSS: Низкий
nvd логотип

CVE-2022-26354

почти 4 года назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 7.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2021-3748

A use-after-free vulnerability was found in the virtio-net device of Q ...

CVSS3: 7.5
0%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2022-9869

ELSA-2022-9869: qemu-kvm security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-9862

ELSA-2022-9862: kvm_utils2 security update (IMPORTANT)

около 3 лет назад
github логотип
GHSA-4f87-mww8-gm8x

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
fstec логотип
BDU:2022-00753

Уязвимость реализации функции virtio_net_receive_rcu (hw/net/virtio-net.c) эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 7.5
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3605-1

Security update for qemu

около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3604-1

Security update for qemu

около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1461-1

Security update for qemu

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3653-1

Security update for qemu

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3605-1

Security update for qemu

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3604-1

Security update for qemu

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3519-1

Security update for qemu

около 4 лет назад
ubuntu логотип
CVE-2022-0897

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-0897

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0897

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0897

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjLis ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-26354

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-26354

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 2.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-26354

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
0%
Низкий
почти 4 года назад

Уязвимостей на страницу