Vulnerabilities > Qemu

DATE CVE VULNERABILITY TITLE RISK
2022-08-29 CVE-2022-0358 Improper Check for Dropped Privileges vulnerability in multiple products
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation.
local
low complexity
qemu redhat CWE-273
7.8
2022-08-26 CVE-2022-0216 Use After Free vulnerability in multiple products
A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU.
local
low complexity
qemu fedoraproject CWE-416
4.4
2022-08-26 CVE-2021-3735 Improper Locking vulnerability in multiple products
A deadlock issue was found in the AHCI controller device of QEMU.
local
low complexity
qemu debian CWE-667
4.4
2022-08-25 CVE-2021-3929 Use After Free vulnerability in multiple products
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU.
local
low complexity
qemu fedoraproject CWE-416
8.2
2022-08-24 CVE-2021-4158 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference issue was found in the ACPI code of QEMU.
local
low complexity
qemu redhat CWE-476
6.0
2022-08-17 CVE-2020-14394 Infinite Loop vulnerability in multiple products
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring.
local
low complexity
qemu fedoraproject redhat CWE-835
3.2
2022-07-11 CVE-2022-35414 Use of Uninitialized Resource vulnerability in multiple products
softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash.
local
low complexity
qemu debian CWE-908
8.8
2022-05-11 CVE-2021-3611 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU.
local
low complexity
qemu redhat CWE-119
6.5
2022-05-02 CVE-2021-3750 Use After Free vulnerability in multiple products
A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU.
local
low complexity
qemu redhat CWE-416
8.2
2022-04-29 CVE-2021-4206 Incorrect Calculation of Buffer Size vulnerability in multiple products
A flaw was found in the QXL display device emulation in QEMU.
local
low complexity
qemu redhat debian CWE-131
8.2