PT-2022-2969 · Qemu+5 · Qemu+5

Muhammad Alifa Ramdhan

+1

·

Published

2021-05-06

·

Updated

2024-06-15

·

CVE-2022-0216

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi do msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1767
ALT-PU-2022-3081
ALT-PU-2022-3083
ALT-PU-2022-3390
ALT-PU-2023-1830
ALT-PU-2023-1869
BDU:2022-03599
CVE-2022-0216
DLA-3362-1
OESA-2022-1907
OPENSUSE-SU-2022_3594-1
OPENSUSE-SU-2022_3660-1
OPENSUSE-SU-2022_3768-1
OPENSUSE-SU-2022_3795-1
OPENSUSE-SU-2024:12209-1
SUSE-SU-2022:3594-1
SUSE-SU-2022:3660-1
SUSE-SU-2022:3768-1
SUSE-SU-2022:3795-1
SUSE-SU-2022_3660-1
SUSE-SU-2022_3795-1
SUSE-SU-2023:0761-1
SUSE-SU-2023:0840-1
SUSE-SU-2023:2358-1
SUSE-SU-2024:1395-1
USN-5772-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Qemu
Suse
Ubuntu