CVE-2021-3713
published 2021-08-25CVE-2021-3713: An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest…
PriorityP338high7.4CVSS 3.1
AVPACLPRLUINSCCHIHAH
EPSS
0.57%
43.6th percentile
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:6.1+dfsg-2 (bookworm) | qemu 1:6.1+dfsg-2 (bookworm) |
| msrc | cbl2_qemu_6.2.0-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_qemu-kvm_4.2.0-36_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | <= 6.1.0 | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11+deb11u1 | 1:5.2+dfsg-11+deb11u1 |
| qemu | qemu | >= 0 < 1:6.1+dfsg-2 | 1:6.1+dfsg-2 |
| qemu | qemu | >= 0 < 1:6.1+dfsg-2 | 1:6.1+dfsg-2 |
| qemu | qemu | >= 0 < 1:6.1+dfsg-2 | 1:6.1+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.39 | 1:2.11+dfsg-1ubuntu7.39 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.21 | 1:4.2-3ubuntu6.21 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.4HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2022-02-28·CVSS 6.5
CVE-2021-3544 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Gaoning Pan discovered that QEMU incorrectly handled the floppy disk
emulator. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2021-20196)
Gaoning Pan discovered that the QEMU vmxnet3 NIC emulator incorrectly
handled certain values. An attacker inside the guest could use this issue
to cause QEMU to crash, resulting in a denial of service. (CVE-2021-20203)
It was discovered that the QEMU vhost-user GPU device contained several
security issues. An attacker inside the guest could use these issues to
cause QEMU to crash, resulting in a denial of service, leak sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubun
Red Hat
QEMU: out-of-bounds write in UAS (USB Attached SCSI) device emulation
vendor_redhat·2021-08-17·CVSS 7.4
CVE-2021-3713 [HIGH] CWE-787 QEMU: out-of-bounds write in UAS (USB Attached SCSI) device emulation
QEMU: out-of-bounds write in UAS (USB Attached SCSI) device emulation
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host.
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash
Microsoft
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked which can lead
vendor_msrc·2021-08-10·CVSS 7.4
CVE-2021-3713 [HIGH] CWE-787 An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked which can lead
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is co
Debian
CVE-2021-3713: qemu - An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emul...
vendor_debian·2021·CVSS 7.4
CVE-2021-3713 [HIGH] CVE-2021-3713: qemu - An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emul...
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host.
Scope: local
bookworm: resolved (fixed in 1:6.1+dfsg-2)
bullseye: resolved (fixed in 1:5.2+dfsg-11+deb11u1)
forky: resolved (fixed in 1:6.1+dfsg-2)
sid: resolved (fixed in 1:6.1+dfsg-2)
trixie: resolved (fixed in 1:6.1+dfsg-2)
GHSA
GHSA-q4w6-2g7p-pr2c: An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6
ghsa_unreviewed·2022-05-24
CVE-2021-3713 [HIGH] CWE-787 GHSA-q4w6-2g7p-pr2c: An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host.
OSV
qemu vulnerabilities
osv·2022-02-28·CVSS 6.5
CVE-2021-20196 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Gaoning Pan discovered that QEMU incorrectly handled the floppy disk
emulator. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2021-20196)
Gaoning Pan discovered that the QEMU vmxnet3 NIC emulator incorrectly
handled certain values. An attacker inside the guest could use this issue
to cause QEMU to crash, resulting in a denial of service. (CVE-2021-20203)
It was discovered that the QEMU vhost-user GPU device contained several
security issues. An attacker inside the guest could use these issues to
cause QEMU to crash, resulting in a denial of service, leak sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubuntu 21.10. (CVE-2021-3544, CVE-2021-3545, CVE-2021-3546)
It w
OSV
CVE-2021-3713: An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6
osv·2021-08-25·CVSS 7.4
CVE-2021-3713 [HIGH] CVE-2021-3713: An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1994640https://lists.debian.org/debian-lts-announce/2021/09/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20210923-0006/https://www.debian.org/security/2021/dsa-4980https://bugzilla.redhat.com/show_bug.cgi?id=1994640https://lists.debian.org/debian-lts-announce/2021/09/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20210923-0006/https://www.debian.org/security/2021/dsa-4980
2021-08-25
Published