CVE-2021-3748

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-3748
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3748.json
Related
Published
2022-03-23T20:15:09Z
Modified
2023-01-03T15:16:38Z
Details

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.

References

Affected packages

Git / github.com/qemu/qemu

Affected ranges

Type
GIT
Repo
https://github.com/qemu/qemu
Events
Type
GIT
Repo
https://gitlab.com/qemu-project/qemu
Events