CVE Database
/

CVE-2022-3872

Back to search

CVE-2022-3872

Published: Nov 7, 2022

Modified: May 5, 2025

PUBLISHED

Description

An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport, respectively, if data_count == block_size. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

VendorProductVersions

n/a

QEMU

affected
Affected: up to latest v7.1.0-rc4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now