CVE-2021-20203: Integer Overflow
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
Other sources
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2021-01/msg07935.html
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20203?
CVE-2021-20203 is an integer overflow issue found in the vmxnet3 NIC emulator of the QEMU virtualization software.
Which versions of QEMU are affected by CVE-2021-20203?
Versions up to and including v5.2.0 of QEMU are affected by CVE-2021-20203.
What is the severity of CVE-2021-20203?
CVE-2021-20203 has a severity rating of low, with a CVSS score of 3.2.
How can a privileged guest user exploit CVE-2021-20203?
A privileged guest user can exploit CVE-2021-20203 by supplying invalid values for rx/tx queue size or other NIC parameters, causing a crash in the QEMU process on the host.
How can I fix CVE-2021-20203?
To fix CVE-2021-20203, update QEMU to a version higher than v5.2.0.