CVE-2022-3872: High severity Qemu Qemu vulnerability
An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhcireaddataport and sdhciwritedataport, respectively, if datacount == blocksize. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3872.
What is the severity of CVE-2022-3872?
The severity of CVE-2022-3872 is high with a score of 8.6.
How does CVE-2022-3872 affect QEMU?
CVE-2022-3872 affects QEMU version up to and excluding 7.1.0.
How can a malicious guest exploit CVE-2022-3872?
A malicious guest could exploit CVE-2022-3872 to crash the QEMU process on the host.
Where can I find more information about CVE-2022-3872?
You can find more information about CVE-2022-3872 in the references: [1](https://lists.nongnu.org/archive/html/qemu-devel/2022-11/msg01068.html), [2](https://security.netapp.com/advisory/ntap-20221215-0005/).