2.1
CVSSv2

CVE-2021-3416

Published: 18/03/2021 Updated: 12/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6 | Impact Score: 4 | Exploitability Score: 1.5
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

fedoraproject fedora 33

redhat enterprise linux 7.0

redhat enterprise linux 6.0

redhat enterprise linux 8.0

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #984448 CVE-2021-3416 Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 3 Mar 2021 19:18:02 UTC Severity: normal Tags: security, upstr ...
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 520 The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario (CVE- ...
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in a denial of service (DoS) scenario ...
Description of Problem Two security issues have been identified in Citrix Hypervisor 82 LTSR, each of which may allow privileged code in a guest VM to cause the host to crash or become unresponsive  These issues only affect Citrix Hypervisor 82 LTSRThese issues have the following CVE identifiers: CVE-2021-3416CVE-2021-20257 CVE IDDescripti ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2021-3416 QEMU: net: infinite loop in loopback mode may lead tostack overflow <!--X-Subject-Header-End--> <!--X-Head-of-Me ...