Out-of-bounds write in QEMU - CVE-2021-3546

 

Out-of-bounds write in QEMU - CVE-2021-3546

Published: May 31, 2021


Vulnerability identifier: #VU53681
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3546
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to a boundary error when processing untrusted input within the virgl_cmd_get_capset() function in vhost-user-gpu/virgl.c. A remote authenticated user of the guest operating system can trigger an out-of-bounds write and escalate privileges.


Affected software

QEMU
Debian Linux
SUSE MicroOS
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
qemu-system-misc (Ubuntu package)
qemu-system-s390x (Ubuntu package)
qemu-system (Ubuntu package)
qemu-system-x86 (Ubuntu package)
qemu-system-sparc (Ubuntu package)
qemu-system-arm (Ubuntu package)
qemu-system-ppc (Ubuntu package)
qemu-system-mips (Ubuntu package)
qemu-seabios
qemu
qemu-debuginfo
qemu-img
qemu-block-ssh
qemu-block-rbd
qemu-block-iscsi
qemu-debugsource
qemu-help
qemu-guest-agent
qemu-audio-pa
qemu-audio-pa-debuginfo
qemu-ui-curses
qemu-ui-curses-debuginfo
qemu-ui-gtk
qemu-ui-gtk-debuginfo
qemu-microvm
qemu-s390
qemu-s390-debuginfo
qemu-block-curl
qemu-block-ssh-debuginfo
qemu-block-rbd-debuginfo
qemu-block-iscsi-debuginfo
qemu-block-curl-debuginfo
qemu-audio-alsa
qemu-x86-debuginfo
qemu-x86
qemu-arm-debuginfo
qemu-arm
qemu-tools-debuginfo
qemu-tools
qemu-audio-alsa-debuginfo
qemu-ppc-debuginfo
qemu-ppc
qemu-kvm
qemu-ui-spice-app-debuginfo
qemu-ui-spice-app
qemu-lang
qemu-guest-agent-debuginfo
qemu-system-x86-microvm (Ubuntu package)
qemu-system-x86-xen (Ubuntu package)
qemu (Debian package)
qemu-skiboot
qemu-chardev-baum
qemu-hw-s390x-virtio-gpu-ccw-debuginfo
qemu-s390x
qemu-s390x-debuginfo
qemu-hw-s390x-virtio-gpu-ccw
qemu-audio-spice-debuginfo
qemu-hw-usb-redirect-debuginfo
qemu-hw-usb-redirect
qemu-hw-display-virtio-vga-debuginfo
qemu-hw-display-virtio-vga
qemu-hw-display-qxl-debuginfo
qemu-hw-display-qxl
qemu-chardev-spice-debuginfo
qemu-chardev-spice
qemu-audio-spice
qemu-ksm
qemu-chardev-baum-debuginfo
qemu-hw-display-virtio-gpu
qemu-hw-display-virtio-gpu-pci-debuginfo
qemu-hw-display-virtio-gpu-pci
qemu-hw-display-virtio-gpu-debuginfo
qemu-ui-opengl
qemu-ui-spice-core-debuginfo
qemu-ui-opengl-debuginfo
qemu-ui-spice-core
qemu-sgabios

How to mitigate CVE-2021-3546

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

qemu-system-misc (Ubuntu package) - addressed in versions 1:2.11+dfsg-1ubuntu7.39, 1:4.2-3ubuntu6.21, 1:6.0+dfsg-2expubuntu1.2
qemu-system-s390x (Ubuntu package) - addressed in versions 1:2.11+dfsg-1ubuntu7.39, 1:4.2-3ubuntu6.21, 1:6.0+dfsg-2expubuntu1.2
qemu-system (Ubuntu package) - addressed in versions 1:2.11+dfsg-1ubuntu7.39, 1:4.2-3ubuntu6.21, 1:6.0+dfsg-2expubuntu1.2
qemu-system-x86 (Ubuntu package) - addressed in versions 1:2.11+dfsg-1ubuntu7.39, 1:4.2-3ubuntu6.21, 1:6.0+dfsg-2expubuntu1.2
qemu-system-sparc (Ubuntu package) - addressed in versions 1:2.11+dfsg-1ubuntu7.39, 1:4.2-3ubuntu6.21, 1:6.0+dfsg-2expubuntu1.2
qemu-system-arm (Ubuntu package) - addressed in versions 1:2.11+dfsg-1ubuntu7.39, 1:4.2-3ubuntu6.21, 1:6.0+dfsg-2expubuntu1.2
qemu-system-ppc (Ubuntu package) - addressed in versions 1:2.11+dfsg-1ubuntu7.39, 1:4.2-3ubuntu6.21, 1:6.0+dfsg-2expubuntu1.2
qemu-system-mips (Ubuntu package) - addressed in versions 1:2.11+dfsg-1ubuntu7.39, 1:4.2-3ubuntu6.21, 1:6.0+dfsg-2expubuntu1.2
qemu-seabios - update to 4.1.0-48
qemu - update to 4.1.0-48
qemu-debuginfo - update to 4.1.0-48
qemu-img - update to 4.1.0-48
qemu-block-ssh - update to 4.1.0-48
qemu-block-rbd - update to 4.1.0-48
qemu-block-iscsi - update to 4.1.0-48
qemu-debugsource - update to 4.1.0-48
qemu-help - update to 4.1.0-48
qemu-guest-agent - update to 4.1.0-48
qemu-audio-pa - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-audio-pa-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-ui-curses - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-ui-curses-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-ui-gtk - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-ui-gtk-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-microvm - update to 4.2.1-11.22.1
qemu-s390 - update to 4.2.1-11.22.1
qemu-s390-debuginfo - update to 4.2.1-11.22.1
qemu-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-block-curl - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-guest-agent - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-block-ssh-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-block-ssh - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-block-rbd-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-block-rbd - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-block-iscsi-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-block-iscsi - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-block-curl-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-audio-alsa - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-x86-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-x86 - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-arm-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-arm - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-tools-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-tools - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-debugsource - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-audio-alsa-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-ppc-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-ppc - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-kvm - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-ui-spice-app-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-ui-spice-app - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-lang - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-guest-agent-debuginfo - addressed in versions 4.2.1-11.22.1, 5.2.0-20.1
qemu-system-x86-microvm (Ubuntu package) - addressed in versions 1:4.2-3ubuntu6.21, 1:6.0+dfsg-2expubuntu1.2
qemu-system-x86-xen (Ubuntu package) - addressed in versions 1:4.2-3ubuntu6.21, 1:6.0+dfsg-2expubuntu1.2
qemu (Debian package) - update to 1:5.2+dfsg-11+deb11u1
qemu-skiboot - update to 5.2.0-20.1
qemu-chardev-baum - update to 5.2.0-20.1
qemu-hw-s390x-virtio-gpu-ccw-debuginfo - update to 5.2.0-20.1
qemu-s390x - update to 5.2.0-20.1
qemu-s390x-debuginfo - update to 5.2.0-20.1
qemu-hw-s390x-virtio-gpu-ccw - update to 5.2.0-20.1
qemu-audio-spice-debuginfo - update to 5.2.0-20.1
qemu-hw-usb-redirect-debuginfo - update to 5.2.0-20.1
qemu-hw-usb-redirect - update to 5.2.0-20.1
qemu-hw-display-virtio-vga-debuginfo - update to 5.2.0-20.1
qemu-hw-display-virtio-vga - update to 5.2.0-20.1
qemu-hw-display-qxl-debuginfo - update to 5.2.0-20.1
qemu-hw-display-qxl - update to 5.2.0-20.1
qemu-chardev-spice-debuginfo - update to 5.2.0-20.1
qemu-chardev-spice - update to 5.2.0-20.1
qemu-audio-spice - update to 5.2.0-20.1
qemu-ksm - update to 5.2.0-20.1
qemu-chardev-baum-debuginfo - update to 5.2.0-20.1
qemu-hw-display-virtio-gpu - update to 5.2.0-20.1
qemu-hw-display-virtio-gpu-pci-debuginfo - update to 5.2.0-20.1
qemu-hw-display-virtio-gpu-pci - update to 5.2.0-20.1
qemu-hw-display-virtio-gpu-debuginfo - update to 5.2.0-20.1
qemu-ui-opengl - update to 5.2.0-20.1
qemu-ui-spice-core-debuginfo - update to 5.2.0-20.1
qemu-ui-opengl-debuginfo - update to 5.2.0-20.1
qemu-ui-spice-core - update to 5.2.0-20.1
qemu-sgabios - addressed in versions 8-11.22.1, 8-20.1

External References

Related Security Bulletins