CVE-2021-4207: Buffer Overflow
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values cursor->header.width and cursor->header.height can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
Other sources
In the QEMU QXL video acelerator a double fetch leads to heap overflow in qxlunpackchunks function.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in the QXL display device emulation in QEMU?
The vulnerability ID is CVE-2021-4207.
What is the severity rating of CVE-2021-4207?
CVE-2021-4207 has a severity rating of 8.2 (high).
What software is affected by CVE-2021-4207?
QEMU qemu, Redhat Enterprise Linux (8.0), Debian Debian Linux (10.0, 11.0), and Ubuntu qemu (kinetic, lunar, bionic, focal, impish, jammy, mantic) are affected by CVE-2021-4207.
What is the description of CVE-2021-4207?
CVE-2021-4207 is a flaw in the QXL display device emulation in QEMU that can lead to a heap-based buffer overflow.
How can I fix CVE-2021-4207?
To fix CVE-2021-4207, update to version 7.0.0 of qemu-kvm (for Redhat) or update to the latest version of QEMU qemu, Redhat Enterprise Linux, Debian Debian Linux, or Ubuntu qemu.