Vulnerability CVE-2022-1050: Information

Description

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Published: March 29, 2022
Modified: March 15, 2023
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
qemusisyphus3.0.0-alt18.2.2-alt3ALT-PU-2018-2161-1211472Fixed
qemusisyphus_e2k7.2.0-alt3.E2K.37.2.0-alt3.E2K.4ALT-PU-2024-1953-1-Fixed
qemup103.0.0-alt18.2.2-alt0.p10.1ALT-PU-2018-2161-1211472Fixed
qemup10_e2k7.2.0-alt3.E2K.07.2.0-alt3.E2K.3ALT-PU-2023-6766-1-Fixed
qemup93.0.0-alt15.2.0-alt6ALT-PU-2018-2161-1211472Fixed
qemuc10f13.0.0-alt18.0.4-alt1.p10ALT-PU-2018-2161-1211472Fixed
qemuc9f23.0.0-alt15.2.0-alt6.c9.1ALT-PU-2018-2161-1211472Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*
      End excliding
      2.20.1