UBUNTU-CVE-2021-3607
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3607
UBUNTU-CVE-2021-3607
Summary:
Details: An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
References: https://ubuntu.com/security/CVE-2021-3607, https://lists.gnu.org/archive/html/qemu-devel/2021-06/msg07925.html, https://ubuntu.com/security/notices/USN-5010-1, https://www.cve.org/CVERecord?id=CVE-2021-3607
Affected packages
Package
Name: qemu
Purl: pkg:deb/ubuntu/qemu@1:4.2-3ubuntu6.17?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
