cbcvebase.
CVE-2022-2962
published 2022-09-13

CVE-2022-2962: A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.38%
30.6th percentile
A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it doesn't check whether the destination address is its own MMIO address. This can cause the device to trigger MMIO handlers multiple times, possibly leading to a stack or heap overflow. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:7.1+dfsg-2 (bookworm)qemu 1:7.1+dfsg-2 (bookworm)
msrcazl3_qemu_6.2.0-18_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_qemu_6.2.0-13_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_qemu-kvm_4.2.0-48_on_cbl_mariner_1.0
qemuqemu
qemuqemu>= 0 < 1:7.1+dfsg-21:7.1+dfsg-2
qemuqemu>= 0 < 1:7.1+dfsg-21:7.1+dfsg-2
qemuqemu>= 0 < 1:7.1+dfsg-21:7.1+dfsg-2
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.411:2.11+dfsg-1ubuntu7.41
qemuqemu>= 0 < 1:4.2-3ubuntu6.241:4.2-3ubuntu6.24
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.61:6.2+dfsg-2ubuntu6.6
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.47+esm22.0.0+dfsg-2ubuntu1.47+esm2
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.51+esm11:2.5+dfsg-5ubuntu10.51+esm1
qemuqemu4.2.0 – 7.1.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.5HIGH
vendor_ubuntu8.5HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.