cbcvebase.
CVE-2021-3930
published 2022-02-18

CVE-2021-3930: An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page'…

medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:6.2+dfsg-1 (bookworm)qemu 1:6.2+dfsg-1 (bookworm)
msrccbl2_qemu_6.2.0-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_qemu-kvm_4.2.0-38_on_cbl_mariner_1.0
qemuqemu< 6.2.06.2.0
qemuqemu
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u3
qemuqemu>= 0 < 1:6.2+dfsg-11:6.2+dfsg-1
qemuqemu>= 0 < 1:6.2+dfsg-11:6.2+dfsg-1
qemuqemu>= 0 < 1:6.2+dfsg-11:6.2+dfsg-1
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.391:2.11+dfsg-1ubuntu7.39
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.411:2.11+dfsg-1ubuntu7.41
qemuqemu>= 0 < 1:4.2-3ubuntu6.211:4.2-3ubuntu6.21
qemuqemu>= 0 < 1:4.2-3ubuntu6.241:4.2-3ubuntu6.24
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.61:6.2+dfsg-2ubuntu6.6
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.47+esm22.0.0+dfsg-2ubuntu1.47+esm2
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.51+esm11:2.5+dfsg-5ubuntu10.51+esm1
redhatcodeready_linux_builder
redhatcodeready_linux_builder_for_ibm_z_systems
redhatcodeready_linux_builder_for_power_little_endian

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
osv8.5HIGH