cbcvebase.
CVE-2021-3713
published 2021-08-25

CVE-2021-3713: An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest…

PriorityP338high7.4CVSS 3.1
AVPACLPRLUINSCCHIHAH
EPSS
0.57%
43.6th percentile
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:6.1+dfsg-2 (bookworm)qemu 1:6.1+dfsg-2 (bookworm)
msrccbl2_qemu_6.2.0-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_qemu-kvm_4.2.0-36_on_cbl_mariner_1.0
qemuqemu<= 6.1.0
qemuqemu
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u11:5.2+dfsg-11+deb11u1
qemuqemu>= 0 < 1:6.1+dfsg-21:6.1+dfsg-2
qemuqemu>= 0 < 1:6.1+dfsg-21:6.1+dfsg-2
qemuqemu>= 0 < 1:6.1+dfsg-21:6.1+dfsg-2
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.391:2.11+dfsg-1ubuntu7.39
qemuqemu>= 0 < 1:4.2-3ubuntu6.211:4.2-3ubuntu6.21

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.4HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.