PT-2021-5460 · Qemu+5 · Qemu+5

Mauro Matteo Cascella

·

Published

2021-05-10

·

Updated

2024-06-15

·

CVE-2021-3544

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions up to and including 6.0
Description The issue is related to several memory leaks found in the virtio vhost-user GPU device of QEMU. These leaks exist in the contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c files due to improper release of memory after its effective lifetime. This can lead to a denial of service.
Recommendations For versions up to and including 6.0, update to a version that includes the fix for the memory leaks in the virtio vhost-user GPU device. As a temporary workaround, consider restricting access to the contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c files to minimize the risk of exploitation.

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2713
ALT-PU-2021-3078
ALT-PU-2021-3363
BDU:2021-06305
CVE-2021-3544
DSA-4980-1
OESA-2021-1227
OPENSUSE-SU-2021:1043-1
OPENSUSE-SU-2021:2213-1
OPENSUSE-SU-2021_1043-1
OPENSUSE-SU-2021_2213-1
OPENSUSE-SU-2024:11287-1
SUSE-SU-2021:2212-1
SUSE-SU-2021:2213-1
SUSE-SU-2021_2212-1
SUSE-SU-2021_2213-1
USN-5010-1
USN-5307-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Qemu
Suse
Ubuntu