CVE-2021-3735
published 2022-08-26CVE-2021-3735: A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS…
PriorityP414medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.20%
9.8th percentile
A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
QEMU: ahci: deadlock issue leads to denial of service
vendor_redhat·2021-08-24·CVSS 4.4
CVE-2021-3735 [MEDIUM] CWE-667 QEMU: ahci: deadlock issue leads to denial of service
QEMU: ahci: deadlock issue leads to denial of service
A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.
A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denia
Debian
CVE-2021-3735: qemu - A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a...
vendor_debian·2021·CVSS 4.4
CVE-2021-3735 [MEDIUM] CVE-2021-3735: qemu - A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a...
A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-ch7h-w2mm-gm7m: A deadlock issue was found in the AHCI controller device of QEMU
ghsa_unreviewed·2022-08-27
CVE-2021-3735 [MEDIUM] CWE-400 GHSA-ch7h-w2mm-gm7m: A deadlock issue was found in the AHCI controller device of QEMU
A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-3735: A deadlock issue was found in the AHCI controller device of QEMU
osv·2022-08-26·CVSS 4.4
CVE-2021-3735 [MEDIUM] CVE-2021-3735: A deadlock issue was found in the AHCI controller device of QEMU
A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3735https://bugzilla.redhat.com/show_bug.cgi?id=1997184https://security-tracker.debian.org/tracker/CVE-2021-3735https://access.redhat.com/security/cve/CVE-2021-3735https://bugzilla.redhat.com/show_bug.cgi?id=1997184https://security-tracker.debian.org/tracker/CVE-2021-3735https://security.netapp.com/advisory/ntap-20250228-0009/
2022-08-26
Published