PT-2021-5461 · Qemu+5 · Qemu+5
Mauro Matteo Cascella
·
Published
2021-08-17
·
Updated
2024-06-15
·
CVE-2021-3713
CVSS v3.1
7.4
High
| Vector | AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QEMU versions prior to 6.2.0-rc0
Description
The issue is related to the UAS (USB Attached SCSI) device emulation of QEMU, where a lack of validation of the stream number can be exploited. This allows an attacker to access confidential data, compromise its integrity, and potentially cause a denial of service. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the
UASDevice->data3 and UASDevice->status3 fields.Recommendations
For QEMU versions prior to 6.2.0-rc0, update to version 6.2.0-rc0 or later to resolve the issue. As a temporary workaround, consider restricting access to the UAS device emulation to minimize the risk of exploitation. Avoid using the
stream number variable in the affected UAS device emulation until the issue is resolved.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Qemu
Suse
Ubuntu