CVE-2022-3165 — Integer Underflow (Wrap or Wraparound) in Qemu
Severity
6.5MEDIUMNVD
OSV8.5
EPSS
0.2%
top 60.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 17
Latest updateDec 12
Description
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
Affected Packages10 packages
Also affects: Fedora 36, 37
Patches
🔴Vulnerability Details
3OSV▶
CVE-2022-3165: An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format↗2022-10-17
GHSA▶
GHSA-3wph-8799-87r7: An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format↗2022-10-17
📋Vendor Advisories
4Microsoft▶
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending ↗2022-10-11
Debian▶
CVE-2022-3165: qemu - An integer underflow issue was found in the QEMU VNC server while processing Cli...↗2022