PT-2022-10649 · Qemu+1 · Qemu+1

·

CVE-2021-3735

·

Published

2022-08-26

·

Updated

2025-02-28

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description A deadlock issue was found in the AHCI controller device of QEMU, occurring on a software reset while handling a host-to-device Register FIS packet from the guest. This could allow a privileged user inside the guest to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this issue is to system availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

DoS

Improper Locking

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3735
ECHO-8C6A-E78A-B98A

Affected Products

Debian
Qemu