Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-0216


A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.


Published

2022-08-26T18:15:08.777

Last Modified

2024-11-21T06:38:09.670

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-416
  • Type: Secondary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qemu qemu < 6.0.0 Yes
Operating System fedoraproject fedora 37 Yes

References