CVE-2021-3608
published 2022-02-24CVE-2021-3608: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a…
PriorityP422medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
EPSS
0.36%
28.6th percentile
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:5.2+dfsg-11 (bookworm) | qemu 1:5.2+dfsg-11 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_qemu-kvm_4.2.0-38_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | < 6.1.0 | 6.1.0 |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11 | 1:5.2+dfsg-11 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11 | 1:5.2+dfsg-11 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11 | 1:5.2+dfsg-11 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11 | 1:5.2+dfsg-11 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.37 | 1:2.11+dfsg-1ubuntu7.37 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.17 | 1:4.2-3ubuntu6.17 |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_msrc6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result i
vendor_msrc·2022-02-08·CVSS 6.0
CVE-2021-3608 [MEDIUM] CWE-824 A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result i
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work whic
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2021-07-15·CVSS 2.3
CVE-2021-3594 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu di
Red Hat
QEMU: pvrdma: uninitialized memory unmap in pvrdma_ring_init()
vendor_redhat·2021-06-17·CVSS 6.0
CVE-2021-3608 [MEDIUM] CWE-824 QEMU: pvrdma: uninitialized memory unmap in pvrdma_ring_init()
QEMU: pvrdma: uninitialized memory unmap in pvrdma_ring_init()
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.
Statement: The versions of `qemu-kv
Debian
CVE-2021-3608: qemu - A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device ...
vendor_debian·2021·CVSS 6.0
CVE-2021-3608 [MEDIUM] CVE-2021-3608: qemu - A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device ...
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-11)
bullseye: resolved (fixed in 1:5.2+dfsg-11)
forky: resolved (fixed in 1:5.2+dfsg-11)
sid: resolved (fixed in 1:5.2+dfsg-11)
trixie: resolved (fixed in 1:5.2+dfsg-11)
GHSA
GHSA-37hv-5w7w-hhjw: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6
ghsa_unreviewed·2022-02-25
CVE-2021-3608 [MEDIUM] CWE-824 GHSA-37hv-5w7w-hhjw: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-3608: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6
osv·2022-02-24·CVSS 6.0
CVE-2021-3608 [MEDIUM] CVE-2021-3608: A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.
OSV
qemu vulnerabilities
osv·2021-07-15·CVSS 2.3
CVE-2020-15469 [LOW] qemu vulnerabilities
qemu vulnerabilities
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu discovered that QEMU incorrectly handled the virtio-fs shared f
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1973383https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2021-06/msg07926.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20220318-0002/https://bugzilla.redhat.com/show_bug.cgi?id=1973383https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2021-06/msg07926.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20220318-0002/
2022-02-24
Published