First published: Mon May 31 2021(Updated: )
A flaw was found in QEMU. Because pvrdma unproperly mremap, a VM escape may be caused.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU qemu | <2.17.2 | |
Debian Debian Linux | =10.0 | |
redhat/qemu | <2.17.2 | 2.17.2 |
debian/qemu | 1:5.2+dfsg-11+deb11u3 1:5.2+dfsg-11+deb11u2 1:7.2+dfsg-7+deb12u7 1:9.2.0+ds-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3582 is a vulnerability found in the QEMU implementation of VMWare's paravirtual RDMA device, which allows a malicious guest to crash the QEMU process on the host.
The severity of CVE-2021-3582 is medium.
QEMU versions up to but excluding 2.17.2, Debian Linux 10.0, Red Hat QEMU versions up to but excluding 2.17.2, and various Ubuntu QEMU versions are affected.
Update QEMU to version 2.17.2 or later, or apply the necessary patches provided by the respective software vendors.
The Common Weakness Enumeration (CWE) associated with CVE-2021-3582 is CWE-119.