UBUNTU-CVE-2021-3416
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3416
UBUNTU-CVE-2021-3416
Summary:
Details: A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.
References: https://ubuntu.com/security/CVE-2021-3416, https://lists.gnu.org/archive/html/qemu-devel/2021-02/msg07431.html, https://lists.gnu.org/archive/html/qemu-devel/2021-02/msg07484.html, https://www.openwall.com/lists/oss-security/2021/02/26/1, https://ubuntu.com/security/notices/USN-5010-1, https://www.cve.org/CVERecord?id=CVE-2021-3416, https://ubuntu.com/security/notices/USN-8412-1
Affected packages
Package
Name: qemu
Purl: pkg:deb/ubuntu/qemu?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
