PT-2021-5459 · Qemu+5 · Qemu+5
Mauro Matteo Cascella
·
Published
2021-05-10
·
Updated
2024-06-15
·
CVE-2021-3545
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
QEMU versions up to and including 6.0
Description
An information disclosure issue exists in the virtio vhost-user GPU device of QEMU, specifically in the
virgl cmd get capset info() function in contrib/vhost-user-gpu/virgl.c. This issue could allow a malicious guest to exploit the flaw and leak memory from the host due to the read of uninitialized memory.Recommendations
For QEMU versions up to and including 6.0, consider updating to a version that includes a fix for this issue, as the current version may allow unauthorized access to confidential data.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Qemu
Suse
Ubuntu