Lucene search

K
osvGoogleOSV:CVE-2021-3607
HistoryFeb 24, 2022 - 7:15 p.m.

CVE-2021-3607

2022-02-2419:15:09
Google
osv.dev
6

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

An integer overflow was found in the QEMU implementation of VMWare’s paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a “PVRDMA_REG_DSRHIGH” write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory, resulting in a denial of service. The highest threat from this vulnerability is to system availability.