8.8
CVSSv3

CVE-2022-35414

Published: 11/07/2022 Updated: 17/05/2024
CVSS v2 Base Score: 6.1 | Impact Score: 8.5 | Exploitability Score: 3.9
CVSS v3 Base Score: 8.8 | Impact Score: 6 | Exploitability Score: 2
VMScore: 543
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:C

Vulnerability Summary

softmmu/physmem.c in QEMU up to and including 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #1014958 qemu: CVE-2022-35414 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 15 Jul 2022 10:33:01 UTC Severity: important Tags: security Reply or subscribe to this bug ...