Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3947

Опубликовано: 10 нояб. 2021
Источник: redhat
CVSS3: 6
EPSS Низкий

Описание

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

Отчет

The qemu-kvm packages as shipped with Red Hat Enterprise Linux are not affected by this flaw as they do not include support for NVMe emulation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 7qemu-kvm-rhevNot affected
Red Hat Enterprise Linux 8virt:rhel/qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmNot affected
Red Hat Enterprise Linux 9qemu-kvmNot affected
Red Hat OpenStack Platform 10 (Newton)qemu-kvm-rhevNot affected
Red Hat OpenStack Platform 13 (Queens)qemu-kvm-rhevNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2021869QEMU: NVMe: out-of-bounds memory read in nvme_changed_nslist

EPSS

Процентиль: 11%
0.00039
Низкий

6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

CVSS3: 5.5
nvd
больше 3 лет назад

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

CVSS3: 5.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 5.5
debian
больше 3 лет назад

A stack-buffer-overflow was found in QEMU in the NVME component. The f ...

CVSS3: 5.5
github
больше 3 лет назад

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

EPSS

Процентиль: 11%
0.00039
Низкий

6 Medium

CVSS3