First published: Mon Jul 11 2022(Updated: )
** DISPUTED ** softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU qemu | >=4.1.50<=7.0.0 | |
Debian Debian Linux | =10.0 | |
>=4.1.50<=7.0.0 | ||
=10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35414 is a vulnerability in QEMU that can cause an uninitialized read on the translate_fail path, leading to a crash.
CVE-2022-35414 can cause an io_readx or io_writex crash in QEMU.
The severity of CVE-2022-35414 is high with a severity score of 8.8.
QEMU versions up to and including 7.0.0 are affected by CVE-2022-35414.
To fix CVE-2022-35414, upgrade QEMU to a version later than 7.0.0.