CVE-2022-35414: High severity Qemu Qemu vulnerability
DISPUTED softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translatefail path, leading to an ioreadx or iowritex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-35414?
CVE-2022-35414 is a vulnerability in QEMU that can cause an uninitialized read on the translate_fail path, leading to a crash.
How does CVE-2022-35414 impact QEMU?
CVE-2022-35414 can cause an io_readx or io_writex crash in QEMU.
What is the severity of CVE-2022-35414?
The severity of CVE-2022-35414 is high with a severity score of 8.8.
Which versions of QEMU are affected by CVE-2022-35414?
QEMU versions up to and including 7.0.0 are affected by CVE-2022-35414.
How can I fix CVE-2022-35414?
To fix CVE-2022-35414, upgrade QEMU to a version later than 7.0.0.