First published: Mon May 10 2021(Updated: )
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized memory. A malicious guest could exploit this issue to leak memory from the host.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU qemu | <=6.0.0 | |
Debian Debian Linux | =11.0 | |
debian/qemu | 1:5.2+dfsg-11+deb11u3 1:5.2+dfsg-11+deb11u2 1:7.2+dfsg-7+deb12u7 1:9.2.0+ds-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this information disclosure vulnerability is CVE-2021-3545.
The severity level of the CVE-2021-3545 vulnerability is medium with a CVSS score of 6.5.
The CVE-2021-3545 vulnerability affects QEMU versions up to and including 6.0.
To fix the CVE-2021-3545 vulnerability, update QEMU to version 6.2 or higher.
You can find more information about the CVE-2021-3545 vulnerability at the following references: [link1], [link2], [link3].