CVE-2021-3700: Use After Free
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparserserialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.
Other sources
An use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in usbredirparserserialize() in usbredirparser/usbredirparser.c when serializing large amounts of buffered write data in case of a slow or blocked destination.
Reference and upstream patch: https://gitlab.freedesktop.org/spice/usbredir/-/commit/03c519ff5831ba
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3700?
CVE-2021-3700 is a use-after-free vulnerability found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c.
How does CVE-2021-3700 occur?
This vulnerability occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.
Which software versions are affected by CVE-2021-3700?
Versions prior to 0.11.0 of usbredir, Spice-space Usbredir, Redhat Enterprise Linux 6.0, Redhat Enterprise Linux 7.0, Redhat Enterprise Linux 8.0, Fedoraproject Fedora 34, and Debian Debian Linux 9.0 are affected by CVE-2021-3700.
What is the severity of CVE-2021-3700?
The severity of CVE-2021-3700 is medium, with a CVSS score of 6.4.
How can CVE-2021-3700 be fixed?
To fix CVE-2021-3700, update usbredir to version 0.11.0 or later.