CVE-2021-3929
published 2022-08-25CVE-2021-3929: A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the…
PriorityP339high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
EPSS
0.64%
46.8th percentile
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:7.0+dfsg-1 (bookworm) | qemu 1:7.0+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_qemu_6.2.0-18_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_qemu_6.2.0-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_qemu-kvm_4.2.0-48_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | < 7.0.0 | 7.0.0 |
| qemu | qemu | >= 0 < 1:7.0+dfsg-1 | 1:7.0+dfsg-1 |
| qemu | qemu | >= 0 < 1:7.0+dfsg-1 | 1:7.0+dfsg-1 |
| qemu | qemu | >= 0 < 1:7.0+dfsg-1 | 1:7.0+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.40 | 1:2.11+dfsg-1ubuntu7.40 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.23 | 1:4.2-3ubuntu6.23 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.2 | 1:6.2+dfsg-2ubuntu6.2 |
| tokio | tokio | >= 0.3.0 < 1.5.1 | 1.5.1 |
| tokio | tokio | >= 1.6.0 < 1.6.3 | 1.6.3 |
| tokio | tokio | >= 1.7.0 < 1.7.2 | 1.7.2 |
| tokio | tokio | >= 1.8.0 < 1.8.1 | 1.8.1 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
osv8.2HIGH
vendor_debian8.2HIGH
vendor_msrc8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and just like it when the reentrancy write triggers the reset function nvm
vendor_msrc·2022-08-09·CVSS 8.2
CVE-2021-3929 [HIGH] CWE-416 A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and just like it when the reentrancy write triggers the reset function nvm
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and just like it when the reentrancy write triggers the reset function nvme_ctrl_reset() data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host resulting in a denial of service condition or potentially executing arbitrary code within the context of the QEMU process on the host.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure vers
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2022-06-21·CVSS 6.1
CVE-2022-26354 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Alexander Bulekov discovered that QEMU incorrectly handled floppy disk
emulation. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly leak
sensitive information. (CVE-2021-3507)
It was discovered that QEMU incorrectly handled NVME controller emulation.
An attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS. (CVE-2021-3929)
It was discovered that QEMU incorrectly handled QXL display device
emulation. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a deni
Red Hat
QEMU: nvme: DMA reentrancy issue leads to use-after-free
vendor_redhat·2021-12-16·CVSS 8.2
CVE-2021-3929 [HIGH] CWE-416 QEMU: nvme: DMA reentrancy issue leads to use-after-free
QEMU: nvme: DMA reentrancy issue leads to use-after-free
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed le
Debian
CVE-2021-3929: qemu - A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation ...
vendor_debian·2021·CVSS 8.2
CVE-2021-3929 [HIGH] CVE-2021-3929: qemu - A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation ...
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.
Scope: local
bookworm: resolved (fixed in 1:7.0+dfsg-1)
bullseye: open
forky: resolved (fixed in 1:7.0+dfsg-1)
sid: resolved (fixed in 1:7.0+dfsg-1)
trixie: resolved (fixed in 1:7.0+dfsg-1)
GHSA
GHSA-h66w-323g-4q62: A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU
ghsa_unreviewed·2022-08-26·CVSS 8.2
CVE-2021-3929 [HIGH] CWE-416 GHSA-h66w-323g-4q62: A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.
OSV
CVE-2021-3929: A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU
osv·2022-08-25·CVSS 8.2
CVE-2021-3929 [HIGH] CVE-2021-3929: A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.
OSV
qemu vulnerabilities
osv·2022-06-21·CVSS 6.1
CVE-2021-3507 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Alexander Bulekov discovered that QEMU incorrectly handled floppy disk
emulation. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly leak
sensitive information. (CVE-2021-3507)
It was discovered that QEMU incorrectly handled NVME controller emulation.
An attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS. (CVE-2021-3929)
It was discovered that QEMU incorrectly handled QXL display device
emulation. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-
OSV
Task dropped in wrong thread when aborting `LocalSet` task
osv·2021-07-07
CVE-2021-38191 Task dropped in wrong thread when aborting `LocalSet` task
Task dropped in wrong thread when aborting `LocalSet` task
When aborting a task with `JoinHandle::abort`, the future is dropped in the
thread calling abort if the task is not currently being executed. This is
incorrect for tasks spawned on a `LocalSet`.
This can easily result in race conditions as many projects use `Rc` or `RefCell`
in their Tokio tasks for better performance.
See [tokio#3929][issue] for more details.
[issue]: https://github.com/tokio-rs/tokio/issues/3929
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3929https://bugzilla.redhat.com/show_bug.cgi?id=2020298https://gitlab.com/qemu-project/qemu/-/commit/736b01642d85be832385https://gitlab.com/qemu-project/qemu/-/issues/556https://gitlab.com/qemu-project/qemu/-/issues/782https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHNN7QJCEQH7AQG5AQP2GEFAQE6K635I/https://access.redhat.com/security/cve/CVE-2021-3929https://bugzilla.redhat.com/show_bug.cgi?id=2020298https://gitlab.com/qemu-project/qemu/-/commit/736b01642d85be832385https://gitlab.com/qemu-project/qemu/-/issues/556https://gitlab.com/qemu-project/qemu/-/issues/782https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHNN7QJCEQH7AQG5AQP2GEFAQE6K635I/https://security.netapp.com/advisory/ntap-20250228-0010/
2022-08-25
Published