Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4158

Опубликовано: 12 дек. 2021
Источник: redhat
CVSS3: 6

Описание

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

Отчет

Releases of Red Hat OpenStack Platform 15 and newer, Red Hat Virtualization 4.4 and newer consume fixes directly from the Red Hat Enterprise Linux 8 Advanced Virtualization repository.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmFix deferred
Red Hat OpenStack Platform 10 (Newton)qemu-kvm-rhevOut of support scope
Red Hat OpenStack Platform 13 (Queens)qemu-kvm-rhevOut of support scope
Red Hat Enterprise Linux 8virt-develFixedRHSA-2022:175910.05.2022
Red Hat Enterprise Linux 8virtFixedRHSA-2022:175910.05.2022
Red Hat Enterprise Linux 9qemu-kvmFixedRHSA-2022:796715.11.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2035002QEMU: NULL pointer dereference in pci_write() in hw/acpi/pcihp.c

6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6
ubuntu
почти 3 года назад

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

CVSS3: 6
nvd
почти 3 года назад

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

CVSS3: 6
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 6
debian
почти 3 года назад

A NULL pointer dereference issue was found in the ACPI code of QEMU. A ...

CVSS3: 6
github
почти 3 года назад

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

6 Medium

CVSS3

Уязвимость CVE-2021-4158