CVE-2021-4206
published 2022-04-29CVE-2021-4206: A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor…
high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:7.0+dfsg-1 (bookworm) | qemu 1:7.0+dfsg-1 (bookworm) |
| msrc | azl3_qemu_6.2.0-18_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_qemu_6.2.0-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_qemu-kvm_4.2.0-41_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | < 7.0.0 | 7.0.0 |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-11+deb11u2 | 1:5.2+dfsg-11+deb11u2 |
| qemu | qemu | >= 0 < 1:7.0+dfsg-1 | 1:7.0+dfsg-1 |
| qemu | qemu | >= 0 < 1:7.0+dfsg-1 | 1:7.0+dfsg-1 |
| qemu | qemu | >= 0 < 1:7.0+dfsg-1 | 1:7.0+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.40 | 1:2.11+dfsg-1ubuntu7.40 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.23 | 1:4.2-3ubuntu6.23 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.2 | 1:6.2+dfsg-2ubuntu6.2 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
osv8.2HIGH
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2022-06-21·CVSS 6.1
CVE-2022-26354 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Alexander Bulekov discovered that QEMU incorrectly handled floppy disk
emulation. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly leak
sensitive information. (CVE-2021-3507)
It was discovered that QEMU incorrectly handled NVME controller emulation.
An attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS. (CVE-2021-3929)
It was discovered that QEMU incorrectly handled QXL display device
emulation. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a deni
Microsoft
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based
vendor_msrc·2022-04-12·CVSS 8.2
CVE-2021-4206 [HIGH] CWE-190 A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transpar
Red Hat
QEMU: QXL: integer overflow in cursor_alloc() can lead to heap buffer overflow
vendor_redhat·2022-03-28·CVSS 8.2
CVE-2021-4206 [HIGH] CWE-190 QEMU: QXL: integer overflow in cursor_alloc() can lead to heap buffer overflow
QEMU: QXL: integer overflow in cursor_alloc() can lead to heap buffer overflow
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbi
Debian
CVE-2021-4206: qemu - A flaw was found in the QXL display device emulation in QEMU. An integer overflo...
vendor_debian·2021·CVSS 8.2
CVE-2021-4206 [HIGH] CVE-2021-4206: qemu - A flaw was found in the QXL display device emulation in QEMU. An integer overflo...
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
Scope: local
bookworm: resolved (fixed in 1:7.0+dfsg-1)
bullseye: resolved (fixed in 1:5.2+dfsg-11+deb11u2)
forky: resolved (fixed in 1:7.0+dfsg-1)
sid: resolved (fixed in 1:7.0+dfsg-1)
trixie: resolved (fixed in 1:7.0+dfsg-1)
OSV
qemu vulnerabilities
osv·2022-06-21·CVSS 6.1
CVE-2021-3507 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Alexander Bulekov discovered that QEMU incorrectly handled floppy disk
emulation. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly leak
sensitive information. (CVE-2021-3507)
It was discovered that QEMU incorrectly handled NVME controller emulation.
An attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS. (CVE-2021-3929)
It was discovered that QEMU incorrectly handled QXL display device
emulation. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-
GHSA
GHSA-rxh4-5vqx-xjq8: A flaw was found in the QXL display device emulation in QEMU
ghsa_unreviewed·2022-04-30
CVE-2021-4206 [HIGH] CWE-190 GHSA-rxh4-5vqx-xjq8: A flaw was found in the QXL display device emulation in QEMU
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
OSV
CVE-2021-4206: A flaw was found in the QXL display device emulation in QEMU
osv·2022-04-29·CVSS 8.2
CVE-2021-4206 [HIGH] CVE-2021-4206: A flaw was found in the QXL display device emulation in QEMU
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2036998https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.gentoo.org/glsa/202208-27https://starlabs.sg/advisories/21-4206/https://www.debian.org/security/2022/dsa-5133https://bugzilla.redhat.com/show_bug.cgi?id=2036998https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20250321-0010/https://starlabs.sg/advisories/21-4206/https://www.debian.org/security/2022/dsa-5133
2022-04-29
Published