Synopsis:
qemu security updateSummary:
An update for qemu is now available for openEuler-24.03-LTS-SP4Description:
QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.
Security Fix(es):
The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. Note: This has been disputed by multiple third parties as not a valid vulnerability due to the rocker device not falling within the virtualization use case.(CVE-2022-36648)Topic:
An update for qemu is now available for openEuler-20.03-LTS-SP1/openEuler-20.03-LTS-SP3/openEuler-22.03-LTS/openEuler-22.03-LTS-SP1/openEuler-22.03-LTS-SP2/master/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS-SP2/openEuler-20.03-LTS-SP4/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.
openEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.Severity:
CriticalAffected Component:
qemu
8.2.0-81.oe2403sp48.2.0-81.oe2403sp48.2.0-81.oe2403sp48.2.0-81.oe2403sp48.2.0-81.oe2403sp48.2.0-81.oe2403sp48.2.0-81.oe2403sp48.2.0-81.oe2403sp48.2.0-81.oe2403sp48.2.0-81.oe2403sp4Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H