An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 3.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Mar 16, 2023 | Aug 17, 2022 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Aug 12, 2024 | Aug 17, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 17, 2022 |
| Suse | — | Upgrade qemu-microvmUpgrade qemu-audio-ossUpgrade qemu-block-curlUpgrade qemu-block-glusterUpgrade qemu-x86Upgrade qemu-hw-display-qxlUpgrade qemu-block-dmgUpgrade qemu-ui-sdlUpgrade qemu-audio-paUpgrade qemuUpgrade qemu-testsuiteUpgrade qemu-block-nfsUpgrade qemu-linux-userUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-s390Upgrade qemu-ui-spice-appUpgrade qemu-ivshmem-toolsUpgrade qemu-toolsUpgrade qemu-audio-sdlUpgrade qemu-chardev-baumUpgrade qemu-audio-jackUpgrade qemu-vhost-user-gpuUpgrade qemu-block-sshUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-guest-agentUpgrade qemu-ui-openglUpgrade qemu-ppcUpgrade qemu-langUpgrade qemu-accel-tcg-x86Upgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-extraUpgrade qemu-kvmUpgrade qemu-s390xUpgrade qemu-ui-spice-coreUpgrade qemu-accel-qtestUpgrade qemu-chardev-spiceUpgrade qemu-audio-spiceUpgrade qemu-block-iscsiUpgrade qemu-block-rbdUpgrade qemu-audio-alsaUpgrade qemu-ipxeUpgrade qemu-seabiosUpgrade qemu-skibootUpgrade qemu-hw-usb-redirectUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-sgabiosUpgrade qemu-hw-usb-smartcardUpgrade qemu-SLOFUpgrade qemu-hw-usb-hostUpgrade qemu-ui-gtkUpgrade qemu-ui-cursesUpgrade qemu-ksmUpgrade qemu-vgabiosUpgrade qemu-arm | Aug 9, 2024 | Aug 17, 2022 |
| Ubuntu | — | Upgrade qemu-systemUpgrade qemu-user-binfmt (Ubuntu Pro)Upgrade qemu-system-mipsUpgrade qemu-system (Ubuntu Pro)Upgrade qemu-kvm (Ubuntu Pro)Upgrade qemu-system-mips (Ubuntu Pro)Upgrade qemu-user-static (Ubuntu Pro)Upgrade qemu-keymaps (Ubuntu Pro)Upgrade qemu (Ubuntu Pro)Upgrade qemu-system-x86Upgrade qemu-system-sparc (Ubuntu Pro)Upgrade qemu-system-sparcUpgrade qemu-system-aarch64 (Ubuntu Pro)Upgrade qemu-utils (Ubuntu Pro)Upgrade qemu-system-x86-xen (Ubuntu Pro)Upgrade qemu-user (Ubuntu Pro)Upgrade qemu-system-ppcUpgrade qemu-system-miscUpgrade qemu-system-armUpgrade qemu-common (Ubuntu Pro)Upgrade qemu-system-x86-microvm (Ubuntu Pro)Upgrade qemuUpgrade qemu-system-common (Ubuntu Pro)Upgrade qemu-system-s390x (Ubuntu Pro)Upgrade qemu-system-x86-microvmUpgrade qemu-system-misc (Ubuntu Pro)Upgrade qemu-system-s390xUpgrade qemu-system-arm (Ubuntu Pro)Upgrade qemu-block-extra (Ubuntu Pro)Upgrade qemu-system-gui (Ubuntu Pro)Upgrade qemu-system-x86-xenUpgrade qemu-guest-agent (Ubuntu Pro)Upgrade qemu-system-data (Ubuntu Pro)Upgrade qemu-system-ppc (Ubuntu Pro)Upgrade qemu-system-x86 (Ubuntu Pro) | Jan 9, 2024 | Aug 17, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub