softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translatefail path, leading to an ioreadx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time.
{ "isDisputed": true }
{ "vanir_signatures": [ { "id": "CVE-2022-35414-489cde29", "target": { "file": "target/loongarch/cpu.c", "function": "loongarch_cpu_reset" }, "signature_version": "v1", "signature_type": "Function", "deprecated": false, "source": "https://github.com/qemu/qemu/commit/3517fb726741c109cae7995f9ea46f0cab6187d6", "digest": { "length": 2415.0, "function_hash": "180636181951544591975415673018936963447" } }, { "id": "CVE-2022-35414-8d4f8493", "target": { "file": "target/loongarch/cpu.c" }, "signature_version": "v1", "signature_type": "Line", "deprecated": false, "source": "https://github.com/qemu/qemu/commit/3517fb726741c109cae7995f9ea46f0cab6187d6", "digest": { "threshold": 0.9, "line_hashes": [ "213631634198854711841217885177925836733", "107642333573383209796745444156070553252", "122648363102556646308346028995137200640", "62414085414761280246786005159634155281" ] } }, { "id": "CVE-2022-35414-e618701c", "target": { "file": "softmmu/physmem.c", "function": "address_space_translate_for_iotlb" }, "signature_version": "v1", "signature_type": "Function", "deprecated": false, "source": "https://github.com/qemu/qemu/commit/418ade7849ce7641c0f7333718caf5091a02fd4c", "digest": { "length": 1043.0, "function_hash": "266490410920851698116572255058293530370" } }, { "id": "CVE-2022-35414-e9004deb", "target": { "file": "softmmu/physmem.c" }, "signature_version": "v1", "signature_type": "Line", "deprecated": false, "source": "https://github.com/qemu/qemu/commit/418ade7849ce7641c0f7333718caf5091a02fd4c", "digest": { "threshold": 0.9, "line_hashes": [ "119017534768101063544275585128909810821", "110879257460673905126937167343309704722", "258474758701097125455151832277555739928", "125944980714841691163617330662659242141", "25848543766198779348294858853397462772", "141357444804312191932535505186420965114", "146285339853103748788579726341031577998", "129067275932782865816605544910082099325", "21645963844557987710304132878129565271", "80447962354397797406542998227256075449", "85637627330814421465952766225951591991", "86152463526257800715083204116907496867" ] } } ] }