CVE-2021-4206: Integer Overflow
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursoralloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
Other sources
In the QEMU QXL video acelerator a integer overflow leads to heap overflow in qxlunpackchunks function.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-4206?
CVE-2021-4206 is a vulnerability found in the QXL display device emulation in QEMU.
What is the severity of CVE-2021-4206?
The severity of CVE-2021-4206 is high with a CVSS score of 8.2.
How does CVE-2021-4206 impact Redhat Enterprise Linux 8.0?
CVE-2021-4206 impacts Redhat Enterprise Linux 8.0.
How can I fix CVE-2021-4206?
To fix CVE-2021-4206, update the affected software to version 7.0.0 or higher.
Where can I find more information about CVE-2021-4206?
You can find more information about CVE-2021-4206 at the following references: [1](https://bugzilla.redhat.com/show_bug.cgi?id=2036998), [2](https://starlabs.sg/advisories/21-4206/), [3](https://www.debian.org/security/2022/dsa-5133).