UBUNTU-CVE-2021-3713
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3713
UBUNTU-CVE-2021-3713
Summary:
Details: An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host.
References: https://ubuntu.com/security/CVE-2021-3713, https://access.redhat.com/security/cve/CVE-2021-3713, https://lists.nongnu.org/archive/html/qemu-devel/2021-08/msg02766.html, https://ubuntu.com/security/notices/USN-5307-1, https://www.cve.org/CVERecord?id=CVE-2021-3713
Affected packages
Package
Name: qemu
Purl: pkg:deb/ubuntu/qemu@1:6.2+dfsg-2ubuntu5?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
