PT-2022-6485 · Qemu+5 · Qemu+5

Mauro Matteo Cascella

·

Published

2018-08-16

·

Updated

2024-10-23

·

CVE-2022-1050

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition. The exploitation of this flaw may allow an attacker to access confidential data, compromise data integrity, and cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2161
ALT-PU-2024-13687
ALT-PU-2024-14149
AZL-9277
BDU:2023-01716
CVE-2022-1050
DLA-3362-1
OESA-2023-1298
OESA-2023-1474
OPENSUSE-SU-2023_3721-1
OPENSUSE-SU-2024:12736-1
SUSE-SU-2023:0671-1
SUSE-SU-2023:0761-1
SUSE-SU-2023:0840-1
SUSE-SU-2023:3721-1
SUSE-SU-2023:3800-1
SUSE-SU-2023_0671-1
USN-6167-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Qemu
Suse
Ubuntu