CVE-2021-3611: Buffer Overflow
A KVM guest can crash qemu-kvm (likely with a stack overflow) when the guest has been started with the intel-hda device. According to the upstream ticket, the crash is due to a stack overflow.
References: https://bugs.launchpad.net/qemu/+bug/1907497 https://gitlab.com/qemu-project/qemu/-/issues/542
Other sources
A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. This flaw affects QEMU versions prior to 7.0.0.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-3611?
CVE-2021-3611 is a stack overflow vulnerability found in the Intel HD Audio device (intel-hda) of QEMU.
How does CVE-2021-3611 affect QEMU?
The vulnerability allows a malicious guest to crash the QEMU process on the host, resulting in a denial of service.
What is the severity of CVE-2021-3611?
CVE-2021-3611 has a severity rating of 6.5, which is considered medium.
Which software versions are affected by CVE-2021-3611?
QEMU versions up to exclusive 7.0.0 and Redhat Enterprise Linux version 8.0 are affected.
How can CVE-2021-3611 be fixed?
Update QEMU to a version higher than 7.0.0 or apply the necessary patches provided by the vendor.