Back to search
CVE-2022-4144
Published: Nov 29, 2022
Modified: Apr 14, 2025
PUBLISHED
Description
An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of service condition.
| Vendor | Product | Versions |
|---|---|---|
n/a | QEMU (QXL device) | affected affects versions up to latest v7.1.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now