Out-of-bounds read in QEMU - CVE-2021-20221
Published: June 22, 2021
Vulnerability identifier: #VU54317
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20221
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform DoS attack.
The vulnerability exists due to an out-of-bounds heap buffer access in the ARM Generic Interrupt Controller emulator of QEMU. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
Affected software
QEMU
Red Hat Enterprise Linux Advanced Virtualization
Red Hat Enterprise Linux Advanced Virtualization
How to mitigate CVE-2021-20221
Install updates from vendor's website.
QEMU - update to 4.2.1