Record summary

CVE-2021-3544 has a selected CVSS score of 6.5 (medium); EIP currently links 1 repository PoC.

Description

Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus

QEMU

CVE ListAll QEMU versions up to and including 6.0affected

Proofs of concept

1

Repository PoCs

GitHubGoultarde/RemoteMouse-3.008-RCERepository PoCby GoultardeStars: 0Not analyzed3 files

41.0 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

6