Integer overflow in QEMU - CVE-2022-4172
Published: February 15, 2023
Vulnerability details
The vulnerability allows a malicious guest to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow within the read_erst_record() and write_erst_record() functions in the ACPI Error Record Serialization Table (ERST) device of QEMU. A malicious guest can overrun the host buffer allocated for the ERST memory device and crash the QEMU process on the host.
Affected software
Gentoo Linux
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Ubuntu
Fedora
Traefik
Red Hat OpenShift Container Platform
qemu-system-sparc (Ubuntu package)
qemu (Ubuntu package)
qemu-system-x86 (Ubuntu package)
qemu-system-ppc (Ubuntu package)
qemu-system (Ubuntu package)
qemu-system-common (Ubuntu package)
qemu-kvm (Ubuntu package)
qemu-guest-agent (Ubuntu package)
qemu-system-aarch64 (Ubuntu package)
qemu-system-s390x (Ubuntu package)
qemu-common (Ubuntu package)
qemu-system-mips (Ubuntu package)
qemu-system-arm (Ubuntu package)
qemu-system-misc (Ubuntu package)
qemu-system-x86-xen (Ubuntu package)
qemu-system-x86-microvm (Ubuntu package)
qemu-system-gui (Ubuntu package)
qemu-system-data (Ubuntu package)
qemu-system-xen (Ubuntu package)
qemu
qemu-kvm (Red Hat package)
app-emulation/qemu
VMware Tanzu Operations Manager
How to mitigate CVE-2022-4172
Red Hat OpenShift Container Platform - update to 4.13.2
qemu-system-sparc (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11
qemu-system-x86 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-system-ppc (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-system (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-system-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-kvm (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.2-3ubuntu6.27
qemu-guest-agent (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-system-aarch64 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
qemu-system-s390x (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-common (Ubuntu package) - update to Ubuntu Pro
qemu-system-mips (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-system-arm (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-system-misc (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
VMware Tanzu Operations Manager - addressed in versions 2.10.59, 3.0.11
qemu-system-x86-xen (Ubuntu package) - addressed in versions 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-system-x86-microvm (Ubuntu package) - addressed in versions 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11
qemu-system-gui (Ubuntu package) - addressed in versions 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-system-data (Ubuntu package) - addressed in versions 1:4.2-3ubuntu6.27, 1:6.2+dfsg-2ubuntu6.11, 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu-system-xen (Ubuntu package) - addressed in versions 1:7.0+dfsg-7ubuntu2.6, 1:7.2+dfsg-5ubuntu2.2
qemu - update to 7.0.0-12.fc37
qemu-kvm (Red Hat package) - update to 7.2.0-14.el9_2
app-emulation/qemu - update to 8.0.0
External References
- https://gitlab.com/qemu-project/qemu/-/commit/defb7098
- https://gitlab.com/qemu-project/qemu/-/issues/1268
- https://lore.kernel.org/qemu-devel/20221024154233.1043347-1-lk@c--e.de/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I7J5IRXJYLELW7D43A75LOWRUE5EU54O/
- https://security.netapp.com/advisory/ntap-20230127-0013/
Related Security Bulletins
- Integer overflow in QEMU
- Traefik update for QEMU
- Red Hat Enterprise Linux 9 update for qemu-kvm
- Multiple vulnerabilities in Oracle Linux
- Ubuntu update for qemu
- VMware Tanzu Operations Manager update for QEMU
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- Gentoo update for QEMU
- Fedora 37 update for qemu