CVE-2021-3546

Related Vulnerabilities: CVE-2021-3546  

A flaw was found in vhost-user-gpu. An out-of-bounds write vulnerability can allow a malicious guest to crash the QEMU process on the host resulting in a denial of service or potentially execute arbitrary code on the host with the privileges of the QEMU process. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Description

A flaw was found in vhost-user-gpu. An out-of-bounds write vulnerability can allow a malicious guest to crash the QEMU process on the host resulting in a denial of service or potentially execute arbitrary code on the host with the privileges of the QEMU process. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Additional Information

  • Bugzilla 1958978: CVE-2021-3546 QEMU: vhost-user-gpu: out-of-bounds write in virgl_cmd_get_capset()
  • CWE-787: Out-of-bounds Write
  • FAQ: Frequently asked questions about CVE-2021-3546