CVE-2021-3392: Use After Free
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsasfreerequest() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.
Other sources
A use-after-free issue was found in the Megaraid emulator of the QEMU. It occurs while processing SCSI i/o requests because in case of an error mptsasfreerequest() does not dequeue request object 'req' from a pending requests' queue. Which later gets processed resulting in the said use-after-free issue. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2021-02/msg00488.html
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/qemuto a version that resolves this vulnerability.Fixed in 6.0.0 - Upgrade
Upgrade
debian/qemuto a version that resolves this vulnerability.Fixed in 1:5.2+dfsg-11+deb11u3Fixed in 1:5.2+dfsg-11+deb11u2Fixed in 1:7.2+dfsg-7+deb12u12Fixed in 1:10.0.0~rc2+ds-2Fixed in 1:10.0.0~rc3+ds-2
Event History
Frequently Asked Questions
What is CVE-2021-3392?
CVE-2021-3392 is a use-after-free flaw found in the MegaRAID emulator of QEMU.
How does CVE-2021-3392 affect QEMU?
CVE-2021-3392 affects QEMU by causing a crash when processing SCSI I/O requests in the case of an error.
What is the severity of CVE-2021-3392?
The severity of CVE-2021-3392 is low with a CVSS score of 3.2.
How can I fix CVE-2021-3392 in QEMU?
To fix CVE-2021-3392 in QEMU, update to version 6.0.0 or apply the provided security patches by the respective vendors.
Where can I find more information about CVE-2021-3392?
More information about CVE-2021-3392 can be found on the MITRE CVE website, the QEMU-devel mailing list, and the Ubuntu Security Notices website.