An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.
[
{
"vendor": "n/a",
"product": "QEMU",
"versions": [
{
"version": "Affected 6.1.0 and later. Will be fixed in 7.2.0-rc0.",
"status": "affected"
}
]
}
]
gitlab.com/qemu-project/qemu/-/commit/d307040b18
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I36LKZA7Z65J3LJU2P37LVTWDFTXBMPU/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTY7TVHX62OJWF6IOBCIGLR2N5K4QN3E/
security.netapp.com/advisory/ntap-20221223-0006/