Lucene search

K
osvGoogleOSV:CVE-2021-4206
HistoryApr 29, 2022 - 5:15 p.m.

CVE-2021-4206

2022-04-2917:15:20
Google
osv.dev
12
qemu
qxl
buffer overflow
arbitrary code execution
integer overflow
heap-based
privileged guest user

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

31.0%

A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.