CVE-2021-20257Infinite Loop in Qemu

CWE-835Infinite Loop8 documents8 sources
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 77.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 16
Latest updateMar 17

Description

An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0

Affected Packages4 packages

NVDqemu/qemu< 6.2.0
Debianqemu/qemu< 1:5.2+dfsg-9+3
CVEListV5qemu/qemuFixed-In v6.2.0
NVDredhat/openstack_platform10.0, 13.0+1

Also affects: Debian Linux 10.0, Fedora 33, Enterprise Linux 6.0, 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-j586-x8f6-9xf2: An infinite loop flaw was found in the e1000 NIC emulator of the QEMU2022-03-17
OSV
CVE-2021-20257: An infinite loop flaw was found in the e1000 NIC emulator of the QEMU2022-03-16
CVEList
CVE-2021-20257: An infinite loop flaw was found in the e1000 NIC emulator of the QEMU2022-03-16

📋Vendor Advisories

4
Microsoft
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized wit2022-03-08
Ubuntu
QEMU vulnerabilities2021-07-15
Red Hat
QEMU: net: e1000: infinite loop while processing transmit descriptors2021-02-10
Debian
CVE-2021-20257: qemu - An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issu...2021
CVE-2021-20257 — Infinite Loop in Qemu | cvebase