2.1
CVSSv2

CVE-2021-20257

Published: 16/03/2022 Updated: 12/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.5 | Impact Score: 4 | Exploitability Score: 2
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

fedoraproject fedora 33

redhat enterprise linux 6.0

redhat enterprise linux 8.0

redhat openstack platform 13.0

redhat openstack platform 10.0

redhat enterprise linux for power little endian 8.0

redhat enterprise linux for ibm z systems 8.0

redhat codeready_linux_builder -

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #984450 CVE-2021-20257 Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 3 Mar 2021 19:21:04 UTC Severity: normal Tags: security, upst ...
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service The highest threat from this vulnerabi ...
An infinite loop issue was found in the e1000 NIC emulator of the QEMU It occurs while processing transmit (tx) descriptors in process_tx_desc, if various descriptor fields are initialised with invalid values A guest may use this flaw to consume CPU cycles on the host resulting in a denial of service (DoS) scenario ...
Description of Problem Two security issues have been identified in Citrix Hypervisor 82 LTSR, each of which may allow privileged code in a guest VM to cause the host to crash or become unresponsive  These issues only affect Citrix Hypervisor 82 LTSRThese issues have the following CVE identifiers: CVE-2021-3416CVE-2021-20257 CVE IDDescripti ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2021-20257 QEMU: net: e1000: infinite loop while processing transmit descriptors <!--X-Subject-Header-End--> <!--X-Head-of ...