AZL-35162
Dashboard / Vulnerabilities / AZL-35162
Summary: CVE-2022-36648 affecting package qemu for versions less than 6.2.0-18
Details: The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. Note: This has been disputed by multiple third parties as not a valid vulnerability due to the rocker device not falling within the virtualization use case.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-36648
Affected packages
Package
Name: qemu
Purl: pkg:rpm/azure-linux/qemu
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -6.2.0-18
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
