Out-of-bounds read in QEMU - CVE-2021-20221

 

Out-of-bounds read in QEMU - CVE-2021-20221

Published: June 22, 2021


Vulnerability identifier: #VU54317
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20221
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform DoS attack.

The vulnerability exists due to an out-of-bounds heap buffer access in the ARM Generic Interrupt Controller emulator of QEMU. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.


Affected software

QEMU
Red Hat Enterprise Linux Advanced Virtualization

How to mitigate CVE-2021-20221

Install updates from vendor's website.

QEMU - update to 4.2.1

External References

Related Security Bulletins