CVE-2021-3392
published 2021-03-23CVE-2021-3392: A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error…
PriorityP410low3.2CVSS 3.1
AVLACLPRHUINSCCNINAL
EPSS
0.45%
36.3th percentile
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:5.2+dfsg-10 (bookworm) | qemu 1:5.2+dfsg-10 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | qemu-img-4.2.0-29.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | qemu-img-4.2.0-29.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | qemu-kvm-4.2.0-29.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | qemu-kvm-4.2.0-29.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-10 | 1:5.2+dfsg-10 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-10 | 1:5.2+dfsg-10 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-10 | 1:5.2+dfsg-10 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-10 | 1:5.2+dfsg-10 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.37 | 1:2.11+dfsg-1ubuntu7.37 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.17 | 1:4.2-3ubuntu6.17 |
| qemu | qemu | 2.10.0 – 5.2.0 | — |
CVSS provenance
nvdv3.13.2LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv3.2LOW
vendor_debian3.2LOW
vendor_msrc3.2LOW
vendor_redhat3.2LOW
vendor_ubuntu2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2021-07-15·CVSS 2.3
CVE-2021-3594 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu di
Microsoft
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request o
vendor_msrc·2021-03-09·CVSS 3.2
CVE-2021-3392 [LOW] CWE-416 A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request o
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Mic
Red Hat
QEMU: scsi: mptsas: use-after-free while processing io requests
vendor_redhat·2021-02-02·CVSS 3.2
CVE-2021-3392 [LOW] CWE-416 QEMU: scsi: mptsas: use-after-free while processing io requests
QEMU: scsi: mptsas: use-after-free while processing io requests
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the
Debian
CVE-2021-3392: qemu - A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occ...
vendor_debian·2021·CVSS 3.2
CVE-2021-3392 [LOW] CVE-2021-3392: qemu - A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occ...
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-10)
bullseye: resolved (fixed in 1:5.2+dfsg-10)
forky: resolved (fixed in 1:5.2+dfsg-10)
sid: resolved (fixed in 1:5.2+dfsg-10)
trixie: resolved (fixed in 1:5.2+dfsg-10)
GHSA
GHSA-466h-jr37-234f: A use-after-free flaw was found in the MegaRAID emulator of QEMU
ghsa_unreviewed·2022-05-24
CVE-2021-3392 [LOW] CWE-416 GHSA-466h-jr37-234f: A use-after-free flaw was found in the MegaRAID emulator of QEMU
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.
OSV
qemu vulnerabilities
osv·2021-07-15·CVSS 2.3
CVE-2020-15469 [LOW] qemu vulnerabilities
qemu vulnerabilities
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu discovered that QEMU incorrectly handled the virtio-fs shared f
OSV
CVE-2021-3392: A use-after-free flaw was found in the MegaRAID emulator of QEMU
osv·2021-03-23·CVSS 3.2
CVE-2021-3392 [LOW] CVE-2021-3392: A use-after-free flaw was found in the MegaRAID emulator of QEMU
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.launchpad.net/qemu/+bug/1914236https://bugzilla.redhat.com/show_bug.cgi?id=1924042https://lists.debian.org/debian-lts-announce/2021/04/msg00009.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.netapp.com/advisory/ntap-20210507-0001/https://bugs.launchpad.net/qemu/+bug/1914236https://bugzilla.redhat.com/show_bug.cgi?id=1924042https://lists.debian.org/debian-lts-announce/2021/04/msg00009.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.netapp.com/advisory/ntap-20210507-0001/
2021-03-23
Published