CVE-2021-3608

MEDIUM

QEMU <6.1.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.

Scores

CVSS v3 6.0
EPSS 0.0004
EPSS Percentile 10.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Details

CWE
CWE-824
Status published
Products (3)
debian/debian_linux 10.0
fedoraproject/fedora 34
qemu/qemu < 6.1.0
Published Feb 24, 2022
Tracked Since Feb 18, 2026