Vulnerability CVE-2021-3546


Published: 2021-06-02

Description:
A flaw was found in vhost-user-gpu of QEMU in versions up to and including 6.0. An out-of-bounds write vulnerability can allow a malicious guest to crash the QEMU process on the host resulting in a denial of service or potentially execute arbitrary code on the host with the privileges of the QEMU process. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Type:

CWE-787

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
QEMU -> QEMU 

 References:
https://bugzilla.redhat.com/show_bug.cgi?id=1958978
http://www.openwall.com/lists/oss-security/2021/05/31/1

Copyright 2024, cxsecurity.com

 

Back to Top