First published: Tue Aug 24 2021(Updated: )
A deadlock issue was found in the AHCI controller device (ich9-ahci) of QEMU while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. The bug is triggered on a software reset (ahci_reset_port) in the handle_reg_h2d_fis() function [1]. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. [1] <a href="https://github.com/qemu/qemu/blob/v6.1.0-rc4/hw/ide/ahci.c#L1215">https://github.com/qemu/qemu/blob/v6.1.0-rc4/hw/ide/ahci.c#L1215</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU qemu | =6.1.0-rc4 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
debian/qemu | <=1:5.2+dfsg-11+deb11u3<=1:5.2+dfsg-11+deb11u2<=1:7.2+dfsg-7+deb12u6<=1:8.2.4+ds-1<=1:9.0.2+ds-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3735 is a deadlock issue found in the AHCI controller device of QEMU.
CVE-2021-3735 occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS packet from the guest.
Users of QEMU versions 1:3.1+dfsg-8+deb10u8 to 1:3.1+dfsg-8+deb10u11, 1:5.2+dfsg-11+deb11u3 to 1:5.2+dfsg-11+deb11u2, 1:7.2+dfsg-7+deb12u2, 1:8.1.1+ds-2, and 1:8.1.2+ds-1, as well as QEMU version 6.1.0-rc4 and Debian Linux versions 10.0 and 11.0 are affected by CVE-2021-3735.
CVE-2021-3735 has a severity score of 4.4 out of 10, which is considered medium.
There is currently no known fix for CVE-2021-3735. It is recommended to update to a patched version of QEMU when it becomes available.