CVE-2022-3165Integer Underflow (Wrap or Wraparound) in Qemu

Severity
6.5MEDIUMNVD
OSV8.5
EPSS
0.2%
top 60.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateDec 12

Description

An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages10 packages

debiandebian/qemu< qemu 1:7.2+dfsg-1 (bookworm)
Debianqemu/qemu< 1:7.2+dfsg-1+2
Ubuntuqemu/qemu< 1:2.11+dfsg-1ubuntu7.41+4
NVDqemu/qemu6.1.07.1.0
CVEListV5qemu/qemuAffected 6.1.0 and later. Will be fixed in 7.2.0-rc0.

Also affects: Fedora 36, 37

Patches

🔴Vulnerability Details

3
OSV
qemu vulnerabilities2022-12-12
OSV
CVE-2022-3165: An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format2022-10-17
GHSA
GHSA-3wph-8799-87r7: An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format2022-10-17

📋Vendor Advisories

4
Ubuntu
QEMU vulnerabilities2022-12-12
Microsoft
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending 2022-10-11
Red Hat
QEMU: VNC: integer underflow in vnc_client_cut_text_ext leads to CPU exhaustion2022-09-25
Debian
CVE-2022-3165: qemu - An integer underflow issue was found in the QEMU VNC server while processing Cli...2022