Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3544

Опубликовано: 02 июн. 2021
Источник: debian
EPSS Низкий

Описание

Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:6.1+dfsg-1package
qemunot-affectedbusterpackage
qemunot-affectedstretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1958935

  • https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01155.html

  • https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01151.html

  • https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01157.html

  • https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01152.html

  • https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01156.html

  • https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01158.html

  • https://gitlab.com/qemu-project/qemu/-/commit/86dd8fac

  • https://gitlab.com/qemu-project/qemu/-/commit/b9f79858

  • https://gitlab.com/qemu-project/qemu/-/commit/b7afebcf

  • https://gitlab.com/qemu-project/qemu/-/commit/f6091d86

  • https://gitlab.com/qemu-project/qemu/-/commit/63736af5

EPSS

Процентиль: 5%
0.00025
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.

CVSS3: 3.2
redhat
около 4 лет назад

Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.

CVSS3: 6.5
nvd
около 4 лет назад

Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.

CVSS3: 6.5
github
около 3 лет назад

Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.

CVSS3: 6.5
fstec
около 4 лет назад

Уязвимость компонентов contrib/vhost-user-gpu/vhost-user-gpu.c и contrib/vhost-user-gpu/virgl.c эмулятора аппаратного обеспечения QEMU, связанная с неправильным освобождением памяти перед удалением последний ссылки, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 5%
0.00025
Низкий