[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-26354Date: (C)2022-03-17   (M)2024-05-24


A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 3.2CVSS Score : 2.1
Exploit Score: 1.5Exploit Score: 3.9
Impact Score: 1.4Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: HIGHAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: CHANGEDIntegrity: NONE
Confidentiality: NONEAvailability: PARTIAL
Integrity: NONE 
Availability: LOW 
  
Reference:
DSA-5133
GLSA-202208-27
https://lists.debian.org/debian-lts-announce/2022/04/msg00002.html
https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html
https://gitlab.com/qemu-project/qemu/-/commit/8d1b247f3748ac4078524130c6d7ae42b6140aaf
https://security.netapp.com/advisory/ntap-20220425-0003/

CWE    1
CWE-772
OVAL    22
oval:org.secpod.oval:def:88465
oval:org.secpod.oval:def:2500706
oval:org.secpod.oval:def:88485
oval:org.secpod.oval:def:1505905
...

© SecPod Technologies