CVE-2022-35414
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time.
** EN DISPUTA ** El archivo softmmu/physmem.c en QEMU versiones hasta 7.0.0, puede llevar a cabo una lectura no inicializada en la ruta translate_fail, conllevando a un bloqueo io_readx o io_writex. NOTA: un tercero afirma que el caso de uso de no virtualización en la referencia de qemu.org se aplica aquí, es decir, "Los errores que afectan al caso de uso de no virtualización no se consideran errores de seguridad en este momento"
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-11 CVE Reserved
- 2022-07-11 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-10-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-908: Use of Uninitialized Resource
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
https://github.com/qemu/qemu/blob/v7.0.0/include/exec/cpu-all.h#L145-L148 | Release Notes | |
https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html | Mailing List | |
https://www.mail-archive.com/qemu-devel%40nongnu.org/msg895266.html | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://sick.codes/sick-2022-113 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://www.qemu.org/docs/master/system/security.html#non-virtualization-use-case | 2024-05-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | >= 4.1.50 <= 7.0.0 Search vendor "Qemu" for product "Qemu" and version " >= 4.1.50 <= 7.0.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|