← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-36648

disputed

The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. Note: This has been disputed by multiple third parties as not a valid vulnerability due to the rocker device not falling within the virtualization use case.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
EPSS Probability:1.40%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.401%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2022-07-25T00:00:00
Published2023-08-22T00:00:00
Last Updated2024-10-03T17:29:51

LINK COPIED TO CLIPBOARD