#VU58813 Use-after-free in QEMU - CVE-2021-3748
Published: December 9, 2021
QEMU
QEMU
Description
The vulnerability allows a remote guest to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when in the virtio-net device of QEMU. A malicious guest can trigger the use-after-free error and execute arbitrary code on the host system with QEMU privileges.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.