An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 3.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Mar 16, 2023 | Aug 17, 2022 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Aug 12, 2024 | Aug 17, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 17, 2022 |
| Suse | — | Upgrade qemu-kvmUpgrade qemu-ivshmem-toolsUpgrade qemu-chardev-baumUpgrade qemu-audio-sdlUpgrade qemu-ui-spice-appUpgrade qemu-block-sshUpgrade qemu-toolsUpgrade qemu-audio-alsaUpgrade qemu-audio-jackUpgrade qemu-s390Upgrade qemu-extraUpgrade qemu-chardev-spiceUpgrade qemu-langUpgrade qemu-ppcUpgrade qemu-ipxeUpgrade qemu-ui-openglUpgrade qemu-ui-spice-coreUpgrade qemu-s390xUpgrade qemu-accel-tcg-x86Upgrade qemu-audio-spiceUpgrade qemu-block-rbdUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-accel-qtestUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-guest-agentUpgrade qemu-block-iscsiUpgrade qemu-vhost-user-gpuUpgrade qemu-audio-ossUpgrade qemu-skibootUpgrade qemu-ui-sdlUpgrade qemu-hw-display-qxlUpgrade qemu-hw-usb-hostUpgrade qemu-ui-gtkUpgrade qemu-ui-cursesUpgrade qemu-seabiosUpgrade qemu-linux-userUpgrade qemu-hw-usb-redirectUpgrade qemu-block-glusterUpgrade qemu-sgabiosUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-microvmUpgrade qemu-testsuiteUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-x86Upgrade qemu-block-nfsUpgrade qemu-block-curlUpgrade qemuUpgrade qemu-ksmUpgrade qemu-vgabiosUpgrade qemu-block-dmgUpgrade qemu-armUpgrade qemu-audio-paUpgrade qemu-SLOFUpgrade qemu-hw-usb-smartcard | Aug 9, 2024 | Aug 17, 2022 |
| Ubuntu | — | Upgrade qemu-system-s390x (Ubuntu Pro)Upgrade qemu-system-x86-xenUpgrade qemu-system-gui (Ubuntu Pro)Upgrade qemu-system-x86-microvmUpgrade qemu-system-x86-microvm (Ubuntu Pro)Upgrade qemuUpgrade qemu-common (Ubuntu Pro)Upgrade qemu-system-miscUpgrade qemu-system-ppc (Ubuntu Pro)Upgrade qemu-system-s390xUpgrade qemu-block-extra (Ubuntu Pro)Upgrade qemu-system-misc (Ubuntu Pro)Upgrade qemu-system-common (Ubuntu Pro)Upgrade qemu-system-data (Ubuntu Pro)Upgrade qemu-system-x86 (Ubuntu Pro)Upgrade qemu-system-arm (Ubuntu Pro)Upgrade qemu-guest-agent (Ubuntu Pro)Upgrade qemu-system-armUpgrade qemu-system-mips (Ubuntu Pro)Upgrade qemu-utils (Ubuntu Pro)Upgrade qemu-system-aarch64 (Ubuntu Pro)Upgrade qemu-system-sparc (Ubuntu Pro)Upgrade qemu-kvm (Ubuntu Pro)Upgrade qemu-system-mipsUpgrade qemu (Ubuntu Pro)Upgrade qemu-systemUpgrade qemu-user-binfmt (Ubuntu Pro)Upgrade qemu-system-ppcUpgrade qemu-system-x86-xen (Ubuntu Pro)Upgrade qemu-keymaps (Ubuntu Pro)Upgrade qemu-system-x86Upgrade qemu-user-static (Ubuntu Pro)Upgrade qemu-system (Ubuntu Pro)Upgrade qemu-system-sparcUpgrade qemu-user (Ubuntu Pro) | Jan 9, 2024 | Aug 17, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub