An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-120"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4172.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "Affected: 7.0.0, Fixed: 7.2.0-rc0"
},
{
"last_affected": "Affected: 7.0.0, Fixed: 7.2.0-rc0"
}
],
"source": "AFFECTED_FIELD"
}
]
}