CVE Database
/

CVE-2022-4144

Back to search

CVE-2022-4144

Published: Nov 29, 2022

Modified: Apr 14, 2025

PUBLISHED

Description

An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of service condition.

VendorProductVersions

n/a

QEMU (QXL device)

affected
affects versions up to latest v7.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now