PT-2022-10649 · Qemu+1 · Qemu+1

Mauro Matteo Cascella

·

Published

2022-08-26

·

Updated

2025-02-28

·

CVE-2021-3735

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description A deadlock issue was found in the AHCI controller device of QEMU, occurring on a software reset while handling a host-to-device Register FIS packet from the guest. This could allow a privileged user inside the guest to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this issue is to system availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

DoS

Improper Locking

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2021-3735

Affected Products

Debian
Qemu