A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.
[
{
"id": "CVE-2022-26353-a9ae21dd",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"target": {
"file": "hw/net/virtio-net.c",
"function": "virtio_net_receive_rcu"
},
"digest": {
"function_hash": "270235561628058841198438626346036432264",
"length": 3016.0
},
"source": "https://gitlab.com/qemu-project/qemu@abe300d9d894f7138e1af7c8e9c88c04bfe98b37"
},
{
"id": "CVE-2022-26353-ce6977f9",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "hw/net/virtio-net.c"
},
"digest": {
"line_hashes": [
"117231405674929910410463275919632308422",
"275513586101648552344315140163073962516",
"31217113160687723639782765688240606782",
"317972341783791818038502029191381494685"
],
"threshold": 0.9
},
"source": "https://gitlab.com/qemu-project/qemu@abe300d9d894f7138e1af7c8e9c88c04bfe98b37"
}
]