发布时间: 2022年5月20日
修改时间: 2024年10月31日
A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.
NVD | openEuler | |
---|---|---|
Confidentiality | None | None |
Attack Vector | Local | Local |
CVSS评分 | 3.2 | 3.2 |
Attack Complexity | Low | Low |
Privileges Required | High | High |
Scope | Changed | Changed |
Integrity | None | None |
User Interaction | None | None |
Availability | Low | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2022-1477 | qemu security update | 2022年5月20日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | qemu | Fixed |
KY3.4-5 | qemu | Fixed |
KY3.5.1 | qemu | Fixed |