PT-2021-3572 · Qemu+6 · Qemu+6

Qiang Liu

·

Published

2021-07-07

·

Updated

2024-06-11

·

CVE-2021-3638

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati 2d blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3585
ALT-PU-2022-1412
ALT-PU-2022-3429
ALT-PU-2023-1830
ALT-PU-2023-1869
AZL-8975
BDU:2021-03673
CVE-2021-3638
DSA-4980-1
OESA-2022-1995
OESA-2022-1996
OESA-2022-1997
OPENSUSE-SU-2023_3721-1
OPENSUSE-SU-2023_4056-1
OPENSUSE-SU-2023_4662-1
SUSE-SU-2023:3444-1
SUSE-SU-2023:3721-1
SUSE-SU-2023:4056-1
SUSE-SU-2023:4662-1
SUSE-SU-2023_3444-1
SUSE-SU-2023_4056-1
SUSE-SU-2023_4662-1
SUSE-SU-2024:0589-1
USN-6567-1
USN-6567-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Qemu
Red Os
Suse
Ubuntu