Lucene search

K
cvelistRedhatCVELIST:CVE-2021-4145
HistoryJan 25, 2022 - 7:11 p.m.

CVE-2021-4145

2022-01-2519:11:14
CWE-476
redhat
www.cve.org
1

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The self pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it’s not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.

CNA Affected

[
  {
    "product": "QEMU",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "qemu-kvm 6.2.0"
      }
    ]
  }
]