Логотип exploitDog
bind:"CVE-2022-26353" OR bind:"CVE-2021-3748" OR bind:"CVE-2022-26354" OR bind:"CVE-2022-0897"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-26353" OR bind:"CVE-2021-3748" OR bind:"CVE-2022-26354" OR bind:"CVE-2022-0897"

Количество 65

Количество 65

msrc логотип

CVE-2021-3748

больше 2 лет назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-3748

около 3 лет назад

A use-after-free vulnerability was found in the virtio-net device of Q ...

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-9869

больше 2 лет назад

ELSA-2022-9869: qemu-kvm security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9862

больше 2 лет назад

ELSA-2022-9862: kvm_utils2 security update (IMPORTANT)

EPSS: Низкий
github логотип

GHSA-4f87-mww8-gm8x

около 3 лет назад

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2022-00753

почти 4 года назад

Уязвимость реализации функции virtio_net_receive_rcu (hw/net/virtio-net.c) эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3605-1

больше 3 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3604-1

больше 3 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1461-1

больше 3 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3653-1

больше 3 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3605-1

больше 3 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3604-1

больше 3 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3519-1

больше 3 лет назад

Security update for qemu

EPSS: Низкий
ubuntu логотип

CVE-2022-0897

около 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-0897

больше 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2022-0897

около 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-0897

около 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjLis ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-26354

больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
EPSS: Низкий
redhat логотип

CVE-2022-26354

больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 2.5
EPSS: Низкий
nvd логотип

CVE-2022-26354

больше 3 лет назад

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 7.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2021-3748

A use-after-free vulnerability was found in the virtio-net device of Q ...

CVSS3: 7.5
0%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2022-9869

ELSA-2022-9869: qemu-kvm security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-9862

ELSA-2022-9862: kvm_utils2 security update (IMPORTANT)

больше 2 лет назад
github логотип
GHSA-4f87-mww8-gm8x

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-00753

Уязвимость реализации функции virtio_net_receive_rcu (hw/net/virtio-net.c) эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 7.5
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:3605-1

Security update for qemu

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3604-1

Security update for qemu

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1461-1

Security update for qemu

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:3653-1

Security update for qemu

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:3605-1

Security update for qemu

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:3604-1

Security update for qemu

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:3519-1

Security update for qemu

больше 3 лет назад
ubuntu логотип
CVE-2022-0897

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-0897

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-0897

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-0897

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjLis ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-26354

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-26354

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 2.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-26354

A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS3: 3.2
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу