OESA-2022-1733
Dashboard / Vulnerabilities / OESA-2022-1733
Summary: qemu security update
Details: QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed. Security Fix(es): A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.(CVE-2021-3929)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1733, https://nvd.nist.gov/vuln/detail/CVE-2021-3929
Affected packages
Package
Name: qemu
Purl: pkg:rpm/openEuler/qemu&distro=openEuler-22.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
