CVE-2021-4145
Dashboard / Vulnerabilities / CVE-2021-4145
Summary:
Details: A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
References: https://security.gentoo.org/glsa/202208-27, https://security.netapp.com/advisory/ntap-20220311-0004/, https://bugzilla.redhat.com/show_bug.cgi?id=2034602, https://gitlab.com/qemu-project/qemu/-/commit/66fed30c9cd11854fc878a4eceb507e915d7c9cd
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- f9baca549e44791be0dd98de15add3d8452a8af0
Fixed -None
Affected versions
6.1.0-NA
6.1.0-rc0
6.1.0-rc1
6.1.0-rc2
6.1.0-rc3
6.1.0-rc4
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
