Lucene search

K
cvelistRedhatCVELIST:CVE-2022-3165
HistoryOct 17, 2022 - 12:00 a.m.

CVE-2022-3165

2022-10-1700:00:00
CWE-191
redhat
www.cve.org
qemu
vnc server
integer underflow
clientcuttext
denial of service

6.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.6%

An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "QEMU",
    "versions": [
      {
        "version": "Affected 6.1.0 and later. Will be fixed in 7.2.0-rc0.",
        "status": "affected"
      }
    ]
  }
]