CVE-2021-20257 — Infinite Loop in Qemu
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 77.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 16
Latest updateMar 17
Description
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0
Affected Packages4 packages
Also affects: Debian Linux 10.0, Fedora 33, Enterprise Linux 6.0, 8.0
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-j586-x8f6-9xf2: An infinite loop flaw was found in the e1000 NIC emulator of the QEMU↗2022-03-17
OSV
▶
CVEList
▶
📋Vendor Advisories
4Microsoft▶
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized wit↗2022-03-08
Debian▶
CVE-2021-20257: qemu - An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issu...↗2021