Lucene search

K
cvelistRedhatCVELIST:CVE-2021-3929
HistoryAug 25, 2022 - 7:36 p.m.

CVE-2021-3929

2022-08-2519:36:36
CWE-416
redhat
www.cve.org
1

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.8%

A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.

CNA Affected

[
  {
    "product": "QEMU",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in qemu-kvm 7.0.0-rc0"
      }
    ]
  }
]