CVE-2021-3582: Buffer Overflow
A flaw was found in QEMU. Because pvrdma unproperly mremap, a VM escape may be caused.
Other sources
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMACMDCREATEMR" command due to improper memory remapping (mremap). This flaw allows a malicious guest to crash the QEMU process on the host. The highest threat from this vulnerability is to system availability.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-3582?
CVE-2021-3582 is a vulnerability found in the QEMU implementation of VMWare's paravirtual RDMA device, which allows a malicious guest to crash the QEMU process on the host.
What is the severity of CVE-2021-3582?
The severity of CVE-2021-3582 is medium.
Which software versions are affected by CVE-2021-3582?
QEMU versions up to but excluding 2.17.2, Debian Linux 10.0, Red Hat QEMU versions up to but excluding 2.17.2, and various Ubuntu QEMU versions are affected.
How can I fix CVE-2021-3582?
Update QEMU to version 2.17.2 or later, or apply the necessary patches provided by the respective software vendors.
What is the Common Weakness Enumeration (CWE) associated with CVE-2021-3582?
The Common Weakness Enumeration (CWE) associated with CVE-2021-3582 is CWE-119.