CVE-2022-1050: Use After Free
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.
Other sources
Guest driver might execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.
Upstream patch: https://lists.nongnu.org/archive/html/qemu-devel/2022-04/msg00273.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-1050?
CVE-2022-1050 is a vulnerability found in the QEMU implementation of VMWare's paravirtual RDMA device, which allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.
How does CVE-2022-1050 impact QEMU?
CVE-2022-1050 can allow a malicious guest driver to execute HW commands in QEMU, potentially leading to a use-after-free condition.
What software versions are affected by CVE-2022-1050?
QEMU versions up to and including 2.20.1, as well as Red Hat QEMU version 8.0.0, are affected by CVE-2022-1050.
What is the severity of CVE-2022-1050?
CVE-2022-1050 has a severity rating of 8.8, which is considered high.
How can I mitigate the risk of CVE-2022-1050?
To mitigate the risk of CVE-2022-1050, it is recommended to update QEMU to a version that includes the fix for this vulnerability.