ZeroHour

CVE-2021-3608

CVSS 3.1
6.0 medium
EPSS
<1%p30
Published
()
Modified
Description

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.

Vendors
qemudebianfedoraproject
Products
qemu, debian linux, fedora
Weakness
CWE-824
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.