CVE-2022-26353

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/03/2022
Last modified:
12/02/2023

Description

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qemu:qemu:6.2.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*