UBUNTU-CVE-2021-3544
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3544
UBUNTU-CVE-2021-3544
Summary:
Details: Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.
References: https://ubuntu.com/security/CVE-2021-3544, https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01155.html, https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01151.html, https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01157.html, https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01152.html, https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01156.html, https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg01158.html, https://ubuntu.com/security/notices/USN-5010-1, https://ubuntu.com/security/notices/USN-5307-1, https://www.cve.org/CVERecord?id=CVE-2021-3544
Affected packages
Package
Name: qemu
Purl: pkg:deb/ubuntu/qemu@1:4.2-3ubuntu6.17?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
