CVE-2021-3582
published 2022-03-25CVE-2021-3582: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to…
PriorityP425medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.39%
31.3th percentile
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to improper memory remapping (mremap). This flaw allows a malicious guest to crash the QEMU process on the host. The highest threat from this vulnerability is to system availability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:5.2+dfsg-11 (bookworm) | qemu 1:5.2+dfsg-11 (bookworm) |
| qemu | qemu | < 2.17.2 | 2.17.2 |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11 | 1:5.2+dfsg-11 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11 | 1:5.2+dfsg-11 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11 | 1:5.2+dfsg-11 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11 | 1:5.2+dfsg-11 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.37 | 1:2.11+dfsg-1ubuntu7.37 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.17 | 1:4.2-3ubuntu6.17 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_cisco3.1
vendor_ubuntu2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2021-07-15·CVSS 2.3
CVE-2021-3594 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu di
Red Hat
QEMU: pvrdma: unproperly mremap in pvrdma_map_to_pdir()
vendor_redhat·2021-06-16·CVSS 6.5
CVE-2021-3582 [MEDIUM] CWE-119 QEMU: pvrdma: unproperly mremap in pvrdma_map_to_pdir()
QEMU: pvrdma: unproperly mremap in pvrdma_map_to_pdir()
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to improper memory remapping (mremap). This flaw allows a malicious guest to crash the QEMU process on the host. The highest threat from this vulnerability is to system availability.
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to improper memory remapping (mremap). This flaw allows a malicious guest to crash the QEMU process on the host. The highest threat from this vulnerability is to system availability.
Statement: The versions of `qemu-kvm` as shipped with Red Hat Enterprise Li
Debian
CVE-2021-3582: qemu - A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device....
vendor_debian·2021·CVSS 6.5
CVE-2021-3582 [MEDIUM] CVE-2021-3582: qemu - A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device....
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to improper memory remapping (mremap). This flaw allows a malicious guest to crash the QEMU process on the host. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-11)
bullseye: resolved (fixed in 1:5.2+dfsg-11)
forky: resolved (fixed in 1:5.2+dfsg-11)
sid: resolved (fixed in 1:5.2+dfsg-11)
trixie: resolved (fixed in 1:5.2+dfsg-11)
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3582 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
CVE-2020-3582: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021 : Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited. Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabiliti
GHSA
GHSA-x7v7-hc56-547j: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device
ghsa_unreviewed·2022-03-26
CVE-2021-3582 [MEDIUM] CWE-119 GHSA-x7v7-hc56-547j: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to improper memory remapping (mremap). This flaw allows a malicious guest to crash the QEMU process on the host. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-3582: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device
osv·2022-03-25·CVSS 6.5
CVE-2021-3582 [MEDIUM] CVE-2021-3582: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to improper memory remapping (mremap). This flaw allows a malicious guest to crash the QEMU process on the host. The highest threat from this vulnerability is to system availability.
OSV
qemu vulnerabilities
osv·2021-07-15·CVSS 2.3
CVE-2020-15469 [LOW] qemu vulnerabilities
qemu vulnerabilities
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu discovered that QEMU incorrectly handled the virtio-fs shared f
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1966266https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20220429-0003/https://bugzilla.redhat.com/show_bug.cgi?id=1966266https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20220429-0003/
2022-03-25
Published