CVE-2022-3165: Fedoraproject Fedora

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.

Affected products

  • Fedoraproject Fedora: version 36 only; version 37 only
  • Qemu Qemu: from 6.1.0, up to and including 7.1.0

Published 2022-10-17. Last modified 2026-06-17.