CVE-2021-3611Improper Restriction of Operations within the Bounds of a Memory Buffer in Qemu

Severity
6.5MEDIUMNVD
OSV3.2
EPSS
0.0%
top 92.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 11
Latest updateJun 6

Description

A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. This flaw affects QEMU versions prior to 7.0.0.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0

Affected Packages4 packages

NVDqemu/qemu< 7.0.0
Debianqemu/qemu< 1:7.0+dfsg-1+2
Ubuntuqemu/qemu< 1:4.2-3ubuntu6.28+3
CVEListV5qemu/qemuQEMU versions prior to 7.0.0

Also affects: Enterprise Linux 8.0

🔴Vulnerability Details

5
OSV
qemu regression2024-06-06
OSV
qemu vulnerabilities2024-01-08
GHSA
GHSA-rj8x-cp5p-j26r: A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU2022-05-12
OSV
CVE-2021-3611: A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU2022-05-11
CVEList
CVE-2021-3611: A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU2022-05-11

📋Vendor Advisories

5
Ubuntu
QEMU regression2024-06-06
Ubuntu
QEMU vulnerabilities2024-01-08
Microsoft
A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host resulting in a denial of service 2022-05-10
Debian
CVE-2021-3611: qemu - A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda...2021
Red Hat
QEMU: intel-hda: segmentation fault due to stack overflow2020-12-09
CVE-2021-3611 — Qemu vulnerability | cvebase