PT-2022-7369 · Qemu+11 · Qemu+11

Mauro Matteo Cascella

+1

·

Published

2020-08-26

·

Updated

2025-02-28

·

CVE-2021-3750

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 7.0.0
Description A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions, such as reset, while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host.
Recommendations For QEMU versions prior to 7.0.0, update to version 7.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the USB EHCI controller emulation to minimize the risk of exploitation. Avoid using crafted content that may trigger undesirable actions in the controller's registers until the issue is resolved.

Exploit

Fix

DoS

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2022:7967
ALSA-2023:6368
ALSA-2023:6980
ALT-PU-2022-2009
ALT-PU-2023-1830
ALT-PU-2023-1869
AZL-35151
AZL-9701
BDU:2024-04421
CESA-2023_6980
CVE-2021-3750
OESA-2022-1679
OPENSUSE-SU-2023_3721-1
OPENSUSE-SU-2023_4056-1
RHSA-2022:7967
RHSA-2022_7967
RHSA-2023:6980
RHSA-2023_6980
RHSA-2024:0404
RHSA-2024:0569
RLSA-2022:7967
SUSE-SU-2023:3444-1
SUSE-SU-2023:3721-1
SUSE-SU-2023:3800-1
SUSE-SU-2023:4056-1
SUSE-SU-2024:1395-1
SUSE-SU-2024_1395-1
USN-5772-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Qemu
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu