UBUNTU-CVE-2021-3682
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3682
UBUNTU-CVE-2021-3682
Summary:
Details: A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
References: https://ubuntu.com/security/CVE-2021-3682, https://ubuntu.com/security/notices/USN-5307-1, https://ubuntu.com/security/notices/USN-5772-1, https://www.cve.org/CVERecord?id=CVE-2021-3682
Affected packages
Package
Name: qemu
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu1.47+esm2?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
