DEBIAN-CVE-2022-36648
Dashboard / Vulnerabilities / DEBIAN-CVE-2022-36648
Summary:
Details: The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. Note: This has been disputed by multiple third parties as not a valid vulnerability due to the rocker device not falling within the virtualization use case.
Affected packages
Package
Name: qemu
Purl: pkg:deb/debian/qemu?arch=source&distro=bookworm
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
1:10.0.0+ds-1
1:10.0.0+ds-2
1:10.0.0+ds-2~bpo12+1
1:10.0.0+ds-2~bpo12+2
1:10.0.0~rc0+ds-1
1:10.0.0~rc0+ds-2
1:10.0.0~rc1+ds-1
1:10.0.0~rc1+ds-2
1:10.0.0~rc2+ds-1
1:10.0.0~rc2+ds-2
1:10.0.0~rc3+ds-1
1:10.0.0~rc3+ds-2
1:10.0.2+ds-1
1:10.0.2+ds-2
1:10.0.2+ds-2~bpo12+1
1:10.0.3+ds-1
1:10.0.3+ds-2
1:10.0.3+ds-3
1:10.0.3+ds-4
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
