OESA-2022-1617
Dashboard / Vulnerabilities / OESA-2022-1617
Summary: qemu security update
Details: QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed. Security Fix(es): An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory, resulting in a denial of service. The highest threat from this vulnerability is to system availability.(CVE-2021-3607) A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.(CVE-2021-3608)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1617, https://nvd.nist.gov/vuln/detail/CVE-2021-3607, https://nvd.nist.gov/vuln/detail/CVE-2021-3608
Affected packages
Package
Name: qemu
Purl: pkg:rpm/openEuler/qemu&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
