CVE-2022-35414

HIGH

Qemu < 7.0.0 - Use of Uninitialized Resource

Title source: rule
STIX 2.1

Description

softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time.

Scores

CVSS v3 8.8
EPSS 0.0030
EPSS Percentile 53.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-908
Status published
Products (2)
debian/debian_linux 10.0
qemu/qemu 4.1.50 - 7.0.0
Published Jul 11, 2022
Tracked Since Feb 18, 2026