cbcvebase.
CVE-2021-3416
published 2021-03-18

CVE-2021-3416: A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in…

PriorityP422medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
EPSS
0.46%
36.7th percentile
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:5.2+dfsg-9 (bookworm)qemu 1:5.2+dfsg-9 (bookworm)
fedoraprojectfedora
msrcqemu-img-4.2.0-29.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcqemu-img-4.2.0-29.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcqemu-kvm-4.2.0-29.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcqemu-kvm-4.2.0-29.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
qemuqemu<= 5.2.0
qemuqemu
qemuqemu>= 0 < 1:5.2+dfsg-91:5.2+dfsg-9
qemuqemu>= 0 < 1:5.2+dfsg-91:5.2+dfsg-9
qemuqemu>= 0 < 1:5.2+dfsg-91:5.2+dfsg-9
qemuqemu>= 0 < 1:5.2+dfsg-91:5.2+dfsg-9
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.371:2.11+dfsg-1ubuntu7.37
qemuqemu>= 0 < 1:4.2-3ubuntu6.171:4.2-3ubuntu6.17
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
ubuntuqemu

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_msrc6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.