CVE-2021-20255
published 2021-03-09CVE-2021-20255: A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.41%
33.6th percentile
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:8.1.0+ds-1 (forky) | qemu 1:8.1.0+ds-1 (forky) |
| msrc | azl3_qemu_6.2.0-18_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-16_on_azure_linux_3.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| qemu | qemu | >= 0 < 1:8.1.0+ds-1 | 1:8.1.0+ds-1 |
| qemu | qemu | >= 0 < 1:8.1.0+ds-1 | 1:8.1.0+ds-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. Th
vendor_msrc·2021-03-09·CVSS 5.5
CVE-2021-20255 [MEDIUM] CWE-674 A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. Th
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host resulting in a denial of service. The highest threat from this vulnerability is to system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is com
Red Hat
QEMU: net: eepro100: stack overflow via infinite recursion
vendor_redhat·2021-02-18·CVSS 5.5
CVE-2021-20255 [MEDIUM] CWE-835 QEMU: net: eepro100: stack overflow via infinite recursion
QEMU: net: eepro100: stack overflow via infinite recursion
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. T
Debian
CVE-2021-20255: qemu - A stack overflow via an infinite recursion vulnerability was found in the eepro1...
vendor_debian·2021·CVSS 5.5
CVE-2021-20255 [MEDIUM] CVE-2021-20255: qemu - A stack overflow via an infinite recursion vulnerability was found in the eepro1...
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:8.1.0+ds-1)
sid: resolved (fixed in 1:8.1.0+ds-1)
trixie: resolved (fixed in 1:8.1.0+ds-1)
GHSA
GHSA-v6w7-gq3g-fwvm: A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU
ghsa_unreviewed·2022-05-24
CVE-2021-20255 [MEDIUM] CWE-674 GHSA-v6w7-gq3g-fwvm: A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-20255: A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU
osv·2021-03-09·CVSS 5.5
CVE-2021-20255 [MEDIUM] CVE-2021-20255: A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1930646https://lists.debian.org/debian-lts-announce/2021/04/msg00009.htmlhttps://ruhr-uni-bochum.sciebo.de/s/NNWP2GfwzYKeKwE?path=%2Feepro100_stackoverflow1https://security.netapp.com/advisory/ntap-20210507-0003/https://www.openwall.com/lists/oss-security/2021/02/25/1https://bugzilla.redhat.com/show_bug.cgi?id=1930646https://lists.debian.org/debian-lts-announce/2021/04/msg00009.htmlhttps://ruhr-uni-bochum.sciebo.de/s/NNWP2GfwzYKeKwE?path=%2Feepro100_stackoverflow1https://security.netapp.com/advisory/ntap-20210507-0003/https://www.openwall.com/lists/oss-security/2021/02/25/1
2021-03-09
Published