{"schema_version":"1.9.0","id":"CVE-2022-26353","published":"2022-03-16T14:02:33Z","modified":"2026-08-12T13:00:31.561579Z","related":["ALSA-2022:5263","ALSA-2022:5821","SUSE-SU-2022:2260-1","openSUSE-SU-2024:12209-1"],"details":"A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qemu/qemu","events":[{"introduced":"44f28df24767cf9dca1ddc9b23157737c4cbb645"},{"last_affected":"44f28df24767cf9dca1ddc9b23157737c4cbb645"}],"database_specific":{"cpe":"cpe:2.3:a:qemu:qemu:6.2.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.2.0"},{"last_affected":"6.2.0"}],"source":"CPE_STRING"}},{"type":"GIT","repo":"https://gitlab.com/qemu-project/qemu","events":[{"introduced":"44f28df24767cf9dca1ddc9b23157737c4cbb645"},{"fixed":"abe300d9d894f7138e1af7c8e9c88c04bfe98b37"}],"database_specific":{"cpe":"cpe:2.3:a:qemu:qemu:6.2.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.2.0"},{"last_affected":"6.2.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["6.2.0","Affected QEMU version: 6.2.0","v6.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-26353.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"270235561628058841198438626346036432264","length":3016},"id":"CVE-2022-26353-a9ae21dd","signature_type":"Function","signature_version":"v1","source":"https://gitlab.com/qemu-project/qemu@abe300d9d894f7138e1af7c8e9c88c04bfe98b37","target":{"file":"hw/net/virtio-net.c","function":"virtio_net_receive_rcu"}},{"deprecated":false,"digest":{"line_hashes":["117231405674929910410463275919632308422","275513586101648552344315140163073962516","31217113160687723639782765688240606782","317972341783791818038502029191381494685"],"threshold":0.9},"id":"CVE-2022-26353-ce6977f9","signature_type":"Line","signature_version":"v1","source":"https://gitlab.com/qemu-project/qemu@abe300d9d894f7138e1af7c8e9c88c04bfe98b37","target":{"file":"hw/net/virtio-net.c"}}],"vanir_signatures_modified":"2026-08-12T13:00:31Z"}}],"references":[{"type":"WEB","url":"https://lists.nongnu.org/archive/html/qemu-devel/2022-03/msg02438.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/26xxx/CVE-2022-26353.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-26353"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202208-27"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220425-0003/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5133"},{"type":"FIX","url":"https://gitlab.com/qemu-project/qemu/-/commit/abe300d9d894f7138e1af7c8e9c88c04bfe98b37"}],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-772"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/26xxx/CVE-2022-26353.json"}}