cbcvebase.
CVE-2021-3748
published 2022-03-23

CVE-2021-3748: A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access…

high7.5CVSS 3.1
AVLACHPRHUINSCCHIHAH
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:6.1+dfsg-6 (bookworm)qemu 1:6.1+dfsg-6 (bookworm)
debianqemu< qemu 1:7.0+dfsg-1 (bookworm)qemu 1:7.0+dfsg-1 (bookworm)
fedoraprojectfedora
msrcazl3_qemu_6.2.0-18_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_qemu_6.2.0-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_qemu-kvm_4.2.0-39_on_cbl_mariner_1.0
qemuqemu
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u21:5.2+dfsg-11+deb11u2
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u11:5.2+dfsg-11+deb11u1
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:6.1+dfsg-61:6.1+dfsg-6
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:6.1+dfsg-61:6.1+dfsg-6

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
osv7.5HIGH