Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-3750

Опубликовано: 02 мая 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.6
CVSS3: 8.2

Описание

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

РелизСтатусПримечание
bionic

released

1:2.11+dfsg-1ubuntu7.41
devel

released

1:7.0+dfsg-7ubuntu1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

1:2.11+dfsg-1ubuntu7.41
esm-infra/focal

not-affected

1:4.2-3ubuntu6.24
esm-infra/xenial

not-affected

code not present
focal

released

1:4.2-3ubuntu6.24
hirsute

ignored

end of life
impish

ignored

end of life
jammy

released

1:6.2+dfsg-2ubuntu6.6

Показывать по

EPSS

Процентиль: 5%
0.00023
Низкий

4.6 Medium

CVSS2

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 5 лет назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
nvd
около 3 лет назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

CVSS3: 8.2
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 8.2
debian
около 3 лет назад

A DMA reentrancy issue was found in the USB EHCI controller emulation ...

CVSS3: 8.2
github
около 3 лет назад

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.

EPSS

Процентиль: 5%
0.00023
Низкий

4.6 Medium

CVSS2

8.2 High

CVSS3