CVE-2021-4145
published 2022-01-25CVE-2021-4145: A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in…
medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:6.2+dfsg-1 (bookworm) | qemu 1:6.2+dfsg-1 (bookworm) |
| msrc | cbl2_qemu_6.2.0-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:6.2+dfsg-1 | 1:6.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-1 | 1:6.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-1 | 1:6.2+dfsg-1 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
osv6.5MEDIUM
Microsoft
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not
vendor_msrc·2022-01-11·CVSS 6.5
CVE-2021-4145 [MEDIUM] CWE-476 A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this w
Red Hat
QEMU: NULL pointer dereference in mirror_wait_on_conflicts() in block/mirror.c
vendor_redhat·2021-12-10·CVSS 6.5
CVE-2021-4145 [MEDIUM] CWE-476 QEMU: NULL pointer dereference in mirror_wait_on_conflicts() in block/mirror.c
QEMU: NULL pointer dereference in mirror_wait_on_conflicts() in block/mirror.c
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
A NULL pointer dereference issue was found in the block mirror layer of QEMU. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
Sta
Debian
CVE-2021-4145: qemu - A NULL pointer dereference issue was found in the block mirror layer of QEMU in ...
vendor_debian·2021·CVSS 6.5
CVE-2021-4145 [MEDIUM] CVE-2021-4145: qemu - A NULL pointer dereference issue was found in the block mirror layer of QEMU in ...
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
Scope: local
bookworm: resolved (fixed in 1:6.2+dfsg-1)
bullseye: resolved
forky: resolved (fixed in 1:6.2+dfsg-1)
sid: resolved (fixed in 1:6.2+dfsg-1)
trixie: resolved (fixed in 1:6.2+dfsg-1)
GHSA
GHSA-j9qg-fc9x-6r3r: A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6
ghsa_unreviewed·2022-01-26
CVE-2021-4145 [MEDIUM] CWE-476 GHSA-j9qg-fc9x-6r3r: A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
OSV
CVE-2021-4145: A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6
osv·2022-01-25·CVSS 6.5
CVE-2021-4145 [MEDIUM] CVE-2021-4145: A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2034602https://gitlab.com/qemu-project/qemu/-/commit/66fed30c9cd11854fc878a4eceb507e915d7c9cdhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20220311-0004/https://bugzilla.redhat.com/show_bug.cgi?id=2034602https://gitlab.com/qemu-project/qemu/-/commit/66fed30c9cd11854fc878a4eceb507e915d7c9cdhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20220311-0004/
2022-01-25
Published