Vulnerability CVE-2021-3638


Published: 2022-03-03   Modified: 2022-03-04

Description:
An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.

 References:
https://bugzilla.redhat.com/show_bug.cgi?id=1979858
https://ubuntu.com/security/CVE-2021-3638
https://lists.nongnu.org/archive/html/qemu-devel/2021-09/msg01682.html

Copyright 2026, cxsecurity.com

 

Back to Top