cbcvebase.
CVE-2021-3682
published 2021-08-05

CVE-2021-3682: A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a…

high8.5CVSS 3.1
AVNACHPRLUINSCCHIHAH
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:6.0+dfsg-3 (bookworm)qemu 1:6.0+dfsg-3 (bookworm)
msrccbl2_qemu_6.2.0-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_qemu-kvm_4.2.0-35_on_cbl_mariner_1.0
qemuqemu< 6.1.06.1.0
qemuqemu
qemuqemu
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u11:5.2+dfsg-11+deb11u1
qemuqemu>= 0 < 1:6.0+dfsg-31:6.0+dfsg-3
qemuqemu>= 0 < 1:6.0+dfsg-31:6.0+dfsg-3
qemuqemu>= 0 < 1:6.0+dfsg-31:6.0+dfsg-3
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.391:2.11+dfsg-1ubuntu7.39
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.411:2.11+dfsg-1ubuntu7.41
qemuqemu>= 0 < 1:4.2-3ubuntu6.211:4.2-3ubuntu6.21
qemuqemu>= 0 < 1:4.2-3ubuntu6.241:4.2-3ubuntu6.24
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.61:6.2+dfsg-2ubuntu6.6
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.47+esm22.0.0+dfsg-2ubuntu1.47+esm2
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.51+esm11:2.5+dfsg-5ubuntu10.51+esm1
redhatenterprise_linux

CVSS provenance

nvdv3.18.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
osv8.5HIGH