Vulnerability CVE-2022-3872: Information
Description
An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport, respectively, if data_count == block_size. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
Severity: HIGH (8.6) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
qemu | sisyphus | 7.2.0-alt1 | 8.2.4-alt1 | ALT-PU-2022-3429-1 | 312523 | Fixed |
qemu | sisyphus_e2k | 7.2.0-alt3.E2K.3 | 7.2.0-alt3.E2K.4 | ALT-PU-2024-1953-1 | - | Fixed |
qemu | sisyphus_riscv64 | 8.0.0-alt0.3.rv64 | 8.0.3-alt0.1.rv64 | ALT-PU-2023-3777-1 | - | Fixed |
qemu | p10 | 8.0.0-alt1.p10 | 8.2.2-alt0.p10.1 | ALT-PU-2023-1830-1 | 320227 | Fixed |
qemu | p10_e2k | 7.2.0-alt3.E2K.0 | 7.2.0-alt3.E2K.3 | ALT-PU-2023-6766-1 | - | Fixed |
qemu | c10f1 | 8.0.0-alt1.p10 | 8.2.2-alt0.p10.1 | ALT-PU-2023-1869-1 | 321192 | Fixed |
qemu | p11 | 7.2.0-alt1 | 8.2.3-alt1 | ALT-PU-2022-3429-1 | 312523 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://lists.nongnu.org/archive/html/qemu-devel/2022-11/msg01068.html |
|
https://security.netapp.com/advisory/ntap-20221215-0005/ |
|