Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3947

Опубликовано: 18 фев. 2022
Источник: debian
EPSS Низкий

Описание

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:6.2+dfsg-1package
qemunot-affectedbullseyepackage
qemunot-affectedbusterpackage
qemunot-affectedstretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2021869

  • Introduced by: https://gitlab.com/qemu-project/qemu/-/commit/f432fdfa1215bc3a00468b2e711176be279b0fd2 (v6.0.0-rc0)

  • https://lore.kernel.org/qemu-devel/20211111153125.2258176-1-philmd@redhat.com/

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e2c57529c9306e4c9aac75d9879f6e7699584a22 (v6.2.0-rc3)

EPSS

Процентиль: 11%
0.00039
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

CVSS3: 6
redhat
больше 3 лет назад

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

CVSS3: 5.5
nvd
больше 3 лет назад

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

CVSS3: 5.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 5.5
github
больше 3 лет назад

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

EPSS

Процентиль: 11%
0.00039
Низкий