• CVE-2022-4172

发布时间: 2022年12月3日

修改时间: 2022年12月9日

概要

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

CVSS v3 指标

NVD openEuler
Confidentiality None
Attack Vector Local
CVSS评分 6.5 0.0
Attack Complexity Low
Privileges Required Low
Scope Changed
Integrity None
User Interaction None
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2022-2668 An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host. 2022年12月3日

影响产品

产品 状态
KY3.4-4A qemu Unaffected
KY3.4-5A qemu Unaffected
KY3.5.1 qemu Unaffected