From b000276d9124c78fc2b69ce1ce9a8bc98f51fe8c Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 27 Sep 2022 08:27:21 +0200 Subject: Add CVE-2022-3165/qemu --- data/CVE/list | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/data/CVE/list b/data/CVE/list index e67bc148ea..085defad54 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -3223,8 +3223,14 @@ CVE-2022-3167 (Improper Restriction of Rendered UI Layers or Frames in GitHub re - rdiffweb (bug #969974) CVE-2022-3166 RESERVED -CVE-2022-3165 +CVE-2022-3165 [VNC: integer underflow in vnc_client_cut_text_ext leads to CPU exhaustion] RESERVED + - qemu + [bullseye] - qemu (Vulnerable code introduced later) + [buster] - qemu (Vulnerable code introduced later) + NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2129739 + NOTE: Introduced by: https://gitlab.com/qemu-project/qemu/-/commit/0bf41cab93e5c72dcda717abd625698b59d9ba3e (v6.1.0-rc0) + NOTE: Proposed fix: https://lists.nongnu.org/archive/html/qemu-devel/2022-09/msg03948.html CVE-2022-3164 RESERVED CVE-2022-3163 -- cgit v1.2.3