Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3735

Опубликовано: 26 авг. 2022
Источник: nvd
CVSS3: 4.4
EPSS Низкий

Описание

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:qemu:qemu:6.1.0:rc4:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

EPSS

Процентиль: 32%
0.00124
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-667
CWE-400

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 3 лет назад

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

CVSS3: 3.2
redhat
больше 4 лет назад

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

CVSS3: 4.4
debian
больше 3 лет назад

A deadlock issue was found in the AHCI controller device of QEMU. It o ...

CVSS3: 4.4
github
больше 3 лет назад

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

EPSS

Процентиль: 32%
0.00124
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-667
CWE-400