CVE-2021-3930
published 2022-02-18CVE-2021-3930: An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page'…
PriorityP424medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.34%
26.0th percentile
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:6.2+dfsg-1 (bookworm) | qemu 1:6.2+dfsg-1 (bookworm) |
| msrc | cbl2_qemu_6.2.0-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_qemu-kvm_4.2.0-38_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | < 6.2.0 | 6.2.0 |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11+deb11u3 | 1:5.2+dfsg-11+deb11u3 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-1 | 1:6.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-1 | 1:6.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-1 | 1:6.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.39 | 1:2.11+dfsg-1ubuntu7.39 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.41 | 1:2.11+dfsg-1ubuntu7.41 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.21 | 1:4.2-3ubuntu6.21 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.24 | 1:4.2-3ubuntu6.24 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.6 | 1:6.2+dfsg-2ubuntu6.6 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.47+esm2 | 2.0.0+dfsg-2ubuntu1.47+esm2 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.51+esm1 | 1:2.5+dfsg-5ubuntu10.51+esm1 |
| redhat | codeready_linux_builder | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_power_little_endian | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv8.5HIGH
vendor_ubuntu8.5HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2022-12-12·CVSS 8.5
CVE-2021-3682 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled bulk transfers from SPICE
clients. A remote attacker could use this issue to cause QEMU to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2021-3682)
It was discovered that QEMU did not properly manage memory when it
transfers the USB packets. A malicious guest attacker could use this issue
to cause QEMU to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2021-3750)
It was discovered that the QEMU SCSI device emulation incorrectly handled
certain MOD
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2022-02-28·CVSS 6.5
CVE-2021-3544 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Gaoning Pan discovered that QEMU incorrectly handled the floppy disk
emulator. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2021-20196)
Gaoning Pan discovered that the QEMU vmxnet3 NIC emulator incorrectly
handled certain values. An attacker inside the guest could use this issue
to cause QEMU to crash, resulting in a denial of service. (CVE-2021-20203)
It was discovered that the QEMU vhost-user GPU device contained several
security issues. An attacker inside the guest could use these issues to
cause QEMU to crash, resulting in a denial of service, leak sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubun
Microsoft
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A
vendor_msrc·2022-02-08·CVSS 6.5
CVE-2021-3930 [MEDIUM] CWE-193 An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU resulting in a denial of service condition.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. S
Red Hat
QEMU: off-by-one error in mode_sense_page() in hw/scsi/scsi-disk.c
vendor_redhat·2021-02-04·CVSS 6.5
CVE-2021-3930 [MEDIUM] CWE-193 QEMU: off-by-one error in mode_sense_page() in hw/scsi/scsi-disk.c
QEMU: off-by-one error in mode_sense_page() in hw/scsi/scsi-disk.c
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the R
Debian
CVE-2021-3930: qemu - An off-by-one error was found in the SCSI device emulation in QEMU. It could occ...
vendor_debian·2021·CVSS 6.5
CVE-2021-3930 [MEDIUM] CVE-2021-3930: qemu - An off-by-one error was found in the SCSI device emulation in QEMU. It could occ...
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
Scope: local
bookworm: resolved (fixed in 1:6.2+dfsg-1)
bullseye: resolved (fixed in 1:5.2+dfsg-11+deb11u3)
forky: resolved (fixed in 1:6.2+dfsg-1)
sid: resolved (fixed in 1:6.2+dfsg-1)
trixie: resolved (fixed in 1:6.2+dfsg-1)
OSV
qemu vulnerabilities
osv·2022-12-12·CVSS 8.5
CVE-2021-3682 [HIGH] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled bulk transfers from SPICE
clients. A remote attacker could use this issue to cause QEMU to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2021-3682)
It was discovered that QEMU did not properly manage memory when it
transfers the USB packets. A malicious guest attacker could use this issue
to cause QEMU to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2021-3750)
It was discovered that the QEMU SCSI device emulation incorrectly handled
certain MODE SELECT commands. An attacker inside the guest could possibl
OSV
qemu vulnerabilities
osv·2022-02-28·CVSS 6.5
CVE-2021-20196 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Gaoning Pan discovered that QEMU incorrectly handled the floppy disk
emulator. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2021-20196)
Gaoning Pan discovered that the QEMU vmxnet3 NIC emulator incorrectly
handled certain values. An attacker inside the guest could use this issue
to cause QEMU to crash, resulting in a denial of service. (CVE-2021-20203)
It was discovered that the QEMU vhost-user GPU device contained several
security issues. An attacker inside the guest could use these issues to
cause QEMU to crash, resulting in a denial of service, leak sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubuntu 21.10. (CVE-2021-3544, CVE-2021-3545, CVE-2021-3546)
It w
GHSA
GHSA-2v9g-p8fq-vvh2: An off-by-one error was found in the SCSI device emulation in QEMU
ghsa_unreviewed·2022-02-19
CVE-2021-3930 [MEDIUM] CWE-193 GHSA-2v9g-p8fq-vvh2: An off-by-one error was found in the SCSI device emulation in QEMU
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
OSV
CVE-2021-3930: An off-by-one error was found in the SCSI device emulation in QEMU
osv·2022-02-18·CVSS 6.5
CVE-2021-3930 [MEDIUM] CVE-2021-3930: An off-by-one error was found in the SCSI device emulation in QEMU
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2020588https://lists.debian.org/debian-lts-announce/2022/04/msg00002.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20220225-0007/https://bugzilla.redhat.com/show_bug.cgi?id=2020588https://lists.debian.org/debian-lts-announce/2022/04/msg00002.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20220225-0007/
2022-02-18
Published