cbcvebase.
CVE-2022-26354
published 2022-03-16

CVE-2022-26354: A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading…

PriorityP48low3.2CVSS 3.1
AVLACLPRHUINSCCNINAL
EPSS
0.39%
31.2th percentile
A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:7.0+dfsg-1 (bookworm)qemu 1:7.0+dfsg-1 (bookworm)
msrcazl3_qemu_6.2.0-18_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_qemu_6.2.0-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_qemu-kvm_4.2.0-48_on_cbl_mariner_1.0
qemuqemu<= 6.2.0
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u21:5.2+dfsg-11+deb11u2
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.401:2.11+dfsg-1ubuntu7.40
qemuqemu>= 0 < 1:4.2-3ubuntu6.231:4.2-3ubuntu6.23
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.21:6.2+dfsg-2ubuntu6.2

CVSS provenance

nvdv3.13.2LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian3.2LOW
vendor_msrc3.2LOW
vendor_redhat3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.