PT-2021-6090 · Qemu+10 · Qemu+10

Mauro Matteo Cascella

·

Published

2021-02-03

·

Updated

2022-12-21

·

CVE-2021-3930

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode sense page() if the page argument was set to MODE PAGE ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Weakness Enumeration

Related Identifiers

ALSA-2021:5238
ALT-PU-2021-3286
ALT-PU-2021-3363
ALT-PU-2021-3585
ALT-PU-2022-2062
ALT-PU-2022-3390
AZL-8671
BDU:2022-00754
CESA-2021_5238
CVE-2021-3930
DLA-2970-1
DLA-3099-1
OPENSUSE-SU-2022:0930-1
OPENSUSE-SU-2022_0930-1
RHSA-2021:5065
RHSA-2021:5238
RHSA-2021_5238
RHSA-2022:0081
RLSA-2021:5238
SUSE-SU-2021:14848-1
SUSE-SU-2021_14848-1
SUSE-SU-2022:0930-1
SUSE-SU-2022:0930-2
SUSE-SU-2022:1151-1
SUSE-SU-2022_0930-1
USN-5307-1
USN-5772-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Qemu
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu