#VU63778 Release of invalid pointer or reference in QEMU - CVE-2021-3682
Published: May 30, 2022
QEMU
QEMU
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists in the USB redirector device emulation of QEMU when dropping packets during a bulk transfer from a SPICE client. A remote user can make QEMU call free() with faked heap chunk metadata to perform a denial of service or escalate privileges on the system.