CVE-2021-3546: High severity Qemu Qemu vulnerability
An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw occurs while processing the 'VIRTIOGPUCMDGETCAPSET' command from the guest. It could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service condition, or potential code execution with the privileges of the QEMU process.
Other sources
An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU. The flaw exists in virglcmdgetcapset() in contrib/vhost-user-gpu/virgl.c and could occur while processing the 'VIRTIOGPUCMDGETCAPSET' command. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
This issue is analogous to CVE-2016-10028 in virtio-gpu-3d: https://bugzilla.redhat.com/showbug.cgi?id=1406367
Patch series: https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg04536.html
OOB write in virglcmdgetcapset() in virgl.c: https://lists.nongnu.org/archive/html/qemu-devel/2021-05/msg04542.html
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qemuto a version that resolves this vulnerability.Fixed in 1:5.2+dfsg-11+deb11u3Fixed in 1:5.2+dfsg-11+deb11u2Fixed in 1:7.2+dfsg-7+deb12u12Fixed in 1:10.0.0~rc3+ds-2
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3546.
What is the severity of CVE-2021-3546?
The severity of CVE-2021-3546 is high with a CVSS score of 8.2.
Which software versions are affected by CVE-2021-3546?
QEMU versions up to and including 6.0 are affected by CVE-2021-3546.
How can I fix CVE-2021-3546?
Apply the patches and updates provided by QEMU, Debian, and Ubuntu to mitigate the vulnerability.
Where can I find more information about CVE-2021-3546?
You can find more information about CVE-2021-3546 on the following references: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1958978), [Debian Security Advisory](https://www.debian.org/security/2021/dsa-4980), [Gentoo Security](https://security.gentoo.org/glsa/202208-27).