CVE-2021-3682
published 2021-08-05CVE-2021-3682: A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a…
high8.5CVSS 3.1
AVNACHPRLUINSCCHIHAH
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:6.0+dfsg-3 (bookworm) | qemu 1:6.0+dfsg-3 (bookworm) |
| msrc | cbl2_qemu_6.2.0-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_qemu-kvm_4.2.0-35_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | < 6.1.0 | 6.1.0 |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11+deb11u1 | 1:5.2+dfsg-11+deb11u1 |
| qemu | qemu | >= 0 < 1:6.0+dfsg-3 | 1:6.0+dfsg-3 |
| qemu | qemu | >= 0 < 1:6.0+dfsg-3 | 1:6.0+dfsg-3 |
| qemu | qemu | >= 0 < 1:6.0+dfsg-3 | 1:6.0+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.39 | 1:2.11+dfsg-1ubuntu7.39 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.41 | 1:2.11+dfsg-1ubuntu7.41 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.21 | 1:4.2-3ubuntu6.21 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.24 | 1:4.2-3ubuntu6.24 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.6 | 1:6.2+dfsg-2ubuntu6.6 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.47+esm2 | 2.0.0+dfsg-2ubuntu1.47+esm2 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.51+esm1 | 1:2.5+dfsg-5ubuntu10.51+esm1 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.18.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
osv8.5HIGH
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2022-12-12·CVSS 8.5
CVE-2021-3682 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled bulk transfers from SPICE
clients. A remote attacker could use this issue to cause QEMU to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2021-3682)
It was discovered that QEMU did not properly manage memory when it
transfers the USB packets. A malicious guest attacker could use this issue
to cause QEMU to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2021-3750)
It was discovered that the QEMU SCSI device emulation incorrectly handled
certain MOD
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2022-02-28·CVSS 6.5
CVE-2021-3544 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Gaoning Pan discovered that QEMU incorrectly handled the floppy disk
emulator. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2021-20196)
Gaoning Pan discovered that the QEMU vmxnet3 NIC emulator incorrectly
handled certain values. An attacker inside the guest could use this issue
to cause QEMU to crash, resulting in a denial of service. (CVE-2021-20203)
It was discovered that the QEMU vhost-user GPU device contained several
security issues. An attacker inside the guest could use these issues to
cause QEMU to crash, resulting in a denial of service, leak sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubun
Microsoft
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being
vendor_msrc·2021-08-10·CVSS 8.5
CVE-2021-3682 [HIGH] CWE-763 A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. M
Red Hat
QEMU: usbredir: free() call on invalid pointer in bufp_alloc()
vendor_redhat·2021-07-19·CVSS 8.5
CVE-2021-3682 [HIGH] CWE-763 QEMU: usbredir: free() call on invalid pointer in bufp_alloc()
QEMU: usbredir: free() call on invalid pointer in bufp_alloc()
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
A flaw was found in the USB redirector device emulation of QEMU. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potent
Debian
CVE-2021-3682: qemu - A flaw was found in the USB redirector device emulation of QEMU in versions prio...
vendor_debian·2021·CVSS 8.5
CVE-2021-3682 [HIGH] CVE-2021-3682: qemu - A flaw was found in the USB redirector device emulation of QEMU in versions prio...
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
Scope: local
bookworm: resolved (fixed in 1:6.0+dfsg-3)
bullseye: resolved (fixed in 1:5.2+dfsg-11+deb11u1)
forky: resolved (fixed in 1:6.0+dfsg-3)
sid: resolved (fixed in 1:6.0+dfsg-3)
trixie: resolved (fixed in 1:6.0+dfsg-3)
OSV
qemu vulnerabilities
osv·2022-12-12·CVSS 8.5
CVE-2021-3682 [HIGH] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled bulk transfers from SPICE
clients. A remote attacker could use this issue to cause QEMU to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2021-3682)
It was discovered that QEMU did not properly manage memory when it
transfers the USB packets. A malicious guest attacker could use this issue
to cause QEMU to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2021-3750)
It was discovered that the QEMU SCSI device emulation incorrectly handled
certain MODE SELECT commands. An attacker inside the guest could possibl
GHSA
GHSA-2w4j-r5v6-3vgr: A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6
ghsa_unreviewed·2022-05-24
CVE-2021-3682 [CRITICAL] CWE-763 GHSA-2w4j-r5v6-3vgr: A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
OSV
qemu vulnerabilities
osv·2022-02-28·CVSS 6.5
CVE-2021-20196 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Gaoning Pan discovered that QEMU incorrectly handled the floppy disk
emulator. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2021-20196)
Gaoning Pan discovered that the QEMU vmxnet3 NIC emulator incorrectly
handled certain values. An attacker inside the guest could use this issue
to cause QEMU to crash, resulting in a denial of service. (CVE-2021-20203)
It was discovered that the QEMU vhost-user GPU device contained several
security issues. An attacker inside the guest could use these issues to
cause QEMU to crash, resulting in a denial of service, leak sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubuntu 21.10. (CVE-2021-3544, CVE-2021-3545, CVE-2021-3546)
It w
OSV
CVE-2021-3682: A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6
osv·2021-08-05·CVSS 8.5
CVE-2021-3682 [HIGH] CVE-2021-3682: A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1989651https://lists.debian.org/debian-lts-announce/2021/09/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20210902-0006/https://www.debian.org/security/2021/dsa-4980https://bugzilla.redhat.com/show_bug.cgi?id=1989651https://lists.debian.org/debian-lts-announce/2021/09/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20210902-0006/https://www.debian.org/security/2021/dsa-4980
2021-08-05
Published