First published: Wed Dec 07 2022(Updated: )
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through 239.255.255.255).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Mirage Firewall | >=0.8.0<0.8.4 | |
>=0.8.0<0.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46770 is a vulnerability in qubes-mirage-firewall 0.8.x through 0.8.3 that allows guest OS users to cause a denial of service via a crafted multicast UDP packet.
CVE-2022-46770 has a severity value of 7.5, categorized as high.
CVE-2022-46770 affects Mirage firewall for QubesOS versions 0.8.0 through 0.8.3.
The denial of service in CVE-2022-46770 can be triggered by guest OS users sending a crafted multicast UDP packet within the IP address range of 224.0.0.0 through 239.255.255.255.
References related to CVE-2022-46770 can be found at http://packetstormsecurity.com/files/171610/Qubes-Mirage-Firewall-0.8.3-Denial-Of-Service.html and https://github.com/mirage/qubes-mirage-firewall/issues/166.