« List of all CVEs

CVE-2022-26353

Published: 3/16/2022 Last updated: 8/3/2024 Reserved: 3/2/2022

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (2)

conf-qemu-img nbd-tool

Products affected (1)

Product Vendor Version
qemu-kvm n/a firmware version 31.0.1 and earlier

References (10)