Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-4172
HistoryNov 29, 2022 - 6:15 p.m.

Integer overflow

2022-11-2918:15:00
PRIOn knowledge base
www.prio-n.com
6
integer overflow
buffer overflow
qemu
acpi erst
guest overrun
host buffer
malicious guest
crash

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.0%

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

CPENameOperatorVersion
fedoraeq37
qemueq7.0.0

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.0%