Lucene search

K
osvGoogleOSV:CVE-2022-36648
HistoryAug 22, 2023 - 7:16 p.m.

CVE-2022-36648

2023-08-2219:16:23
Google
osv.dev
8
hardware emulation
qemu
rocker device
remote execution

7.6 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.9%

The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS.

7.6 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.9%