Description
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.
References (5)
Scores
CVSS v3
6.0
EPSS
0.0004
EPSS Percentile
10.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Details
CWE
CWE-824
Status
published
Products (3)
debian/debian_linux
10.0
fedoraproject/fedora
34
qemu/qemu
< 6.1.0
Published
Feb 24, 2022
Tracked Since
Feb 18, 2026