QEMU Rocker L2 Flood causes host crash possible RCE (v7.0.0-)
CVE-2022-36648 Published on August 22, 2023

The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. Note: This has been disputed by multiple third parties as not a valid vulnerability due to the rocker device not falling within the virtualization use case.

NVD


Products Associated with CVE-2022-36648

Want to know whenever a new CVE is published for QEMU? stack.watch will email you.

 

Exploit Probability

EPSS
1.24%
Percentile
78.97%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.