CVE-2022-3165: Integer Underflow
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format [1]. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service condition.
[1] https://github.com/rfbproto/rfbproto/blob/master/rfbproto.rst#extended-clipboard-pseudo-encoding
Other sources
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-3165.
What is the severity of CVE-2022-3165?
The severity of CVE-2022-3165 is medium with a CVSS score of 6.5.
What is the affected software for CVE-2022-3165?
The affected software for CVE-2022-3165 includes QEMU versions up to 7.1.0, Ubuntu QEMU versions 1:6.2+dfsg-2ubuntu6.6 and 1:7.0+dfsg-7ubuntu2.1, Red Hat QEMU version 7.2.0, Fedora versions 36 and 37, and Debian QEMU versions 1:3.1+dfsg-8+deb10u8, 1:3.1+dfsg-8+deb10u11, 1:5.2+dfsg-11+deb11u3, 1:5.2+dfsg-11+deb11u2, 1:7.2+dfsg-7+deb12u2, and 1:8.1.2+ds-1.
How can a malicious client exploit CVE-2022-3165?
A malicious client can exploit CVE-2022-3165 by sending a specially crafted payload message to the QEMU VNC server while processing ClientCutText messages in the extended format.
What is the remedy for CVE-2022-3165?
The remedy for CVE-2022-3165 is to update QEMU to the recommended versions: Ubuntu QEMU 1:6.2+dfsg-2ubuntu6.6 or 1:7.0+dfsg-7ubuntu2.1, Red Hat QEMU 7.2.0, or Debian QEMU 1:3.1+dfsg-8+deb10u8, 1:3.1+dfsg-8+deb10u11, 1:5.2+dfsg-11+deb11u3, 1:5.2+dfsg-11+deb11u2, 1:7.2+dfsg-7+deb12u2, or 1:8.1.2+ds-1.