UBUNTU-CVE-2021-20221

    Dashboard / Vulnerabilities / UBUNTU-CVE-2021-20221

    UBUNTU-CVE-2021-20221

    Published: 13 May 2021Last Modified: 9 Jun 2026

    Summary:

    Details: An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields and their subsequent processing. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.

    Affected packages

    Package

    Name: qemu

    Purl: pkg:deb/ubuntu/qemu?arch=source&distro=esm-infra-legacy%2Ftrusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.0.0+dfsg-2ubuntu1.47+esm6

    Affected versions

    1.5.0+dfsg-3ubuntu5
    1.5.0+dfsg-3ubuntu6

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2021-20221 | CVE-DB