Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-4158

Опубликовано: 24 авг. 2022
Источник: debian
EPSS Низкий

Описание

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:6.2+dfsg-2package
qemunot-affectedbullseyepackage
qemunot-affectedbusterpackage
qemunot-affectedstretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2035002

  • https://gitlab.com/qemu-project/qemu/-/issues/770

  • Introduced in: https://gitlab.com/qemu-project/qemu/-/commit/b32bd763a1ca929677e22ae1c51cb3920921bdce (v6.0.0-rc0)

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/9bd6565ccee68f72d5012e24646e12a1c662827e

  • https://lists.nongnu.org/archive/html/qemu-devel/2021-12/msg03692.html

EPSS

Процентиль: 1%
0.00011
Низкий

Связанные уязвимости

CVSS3: 6
ubuntu
почти 3 года назад

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

CVSS3: 6
redhat
больше 3 лет назад

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

CVSS3: 6
nvd
почти 3 года назад

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

CVSS3: 6
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 6
github
почти 3 года назад

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

EPSS

Процентиль: 1%
0.00011
Низкий