[WID-SEC-2022-0282] QEMU: Mehrere Schwachstellen CVSS Base Score 8.2 (hoch) CVSS Temporal Score 7.1 (hoch) Remoteangriff nein Datum 01.05.2022 Stand UPDATE 10.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges Windows Produktbeschreibung QEMU ist eine freie Virtualisierungssoftware, die die gesamte Hardware eines Computers emuliert. Produkte UPDATE 05.06.2023 Amazon Linux 2 UPDATE 02.08.2022 Oracle Linux UPDATE 04.07.2022 SUSE Linux UPDATE 21.06.2022 Ubuntu Linux UPDATE 13.06.2022 Red Hat Enterprise Linux UPDATE 09.05.2022 Debian Linux 01.05.2022 Open Source QEMU Angriff Angriff Ein lokaler Angreifer kann mehrere Schwachstelle in QEMU ausnutzen, um einen Denial of Service Angriff durchzuführen und beliebigen Code auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in QEMU (CVSS Base Score 8.2) allow a local attacker to cause a denial of service and execute arbitrary code. The advisory notes that major Linux distributions, including Amazon Linux 2, Oracle Linux, SUSE Linux, Ubuntu Linux, Red Hat Enterprise Linux, and Debian Linux, have released updates to address these issues. A mitigation is available, though the specific workaround is not detailed in the provided text.