Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-3582
HistoryJun 18, 2021 - 12:00 a.m.

CVE-2021-3582

2021-06-1800:00:00
ubuntu.com
ubuntu.com
19
qemu
vmware
paravirtual
rdma
memory remapping
mremap
crash
system availability
vulnerability

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

EPSS

0.001

Percentile

30.2%

A flaw was found in the QEMU implementation of VMWare’s paravirtual RDMA
device. The issue occurs while handling a “PVRDMA_CMD_CREATE_MR” command
due to improper memory remapping (mremap). This flaw allows a malicious
guest to crash the QEMU process on the host. The highest threat from this
vulnerability is to system availability.

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchqemu< 1:4.2-3ubuntu6.17UNKNOWN
ubuntu20.10noarchqemu< 1:5.0-5ubuntu9.9UNKNOWN
ubuntu21.04noarchqemu< 1:5.2+dfsg-9ubuntu3.1UNKNOWN
ubuntu21.10noarchqemu< 1:6.0+dfsg-2expubuntu1UNKNOWN
ubuntu22.04noarchqemu< 1:6.0+dfsg-2expubuntu1UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

EPSS

0.001

Percentile

30.2%