Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-4144


An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of service condition.


Published

2022-11-29T18:15:10.550

Last Modified

2025-04-14T18:15:24.910

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qemu qemu ≤ 7.1.0 Yes
Application fedoraproject extra_packages_for_enterprise_linux 8.0 Yes
Operating System fedoraproject fedora 37 Yes
Operating System redhat enterprise_linux 8.0 Yes

References