3.6
CVSSv2

CVE-2021-3507

Published: 06/05/2021 Updated: 12/02/2023
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.1 | Impact Score: 4.2 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

It exists that QEMU incorrectly handled QXL display device emulation. A privileged attacker inside the guest could use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-4206, CVE-2021-4207)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

debian debian linux 10.0

redhat enterprise linux 8.0

Vendor Advisories

Debian Bug report logs - #987410 qemu: CVE-2021-3507 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Apr 2021 13:00:02 UTC Severity: important Tags: security, upstream Found in versions qemu/1 ...
Several security issues were fixed in QEMU ...
Synopsis Low: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterpri ...
Synopsis Moderate: qemu-kvm security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for qemu-kvm is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rate ...
A heap buffer overflow was found in the floppy disk emulator of QEMU It could occur in fdctrl_transfer_handler() in hw/block/fdcc while processing DMA read data transfers from the floppy drive to the guest system A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information ...
A heap buffer overflow was found in the floppy disk emulator of QEMU It could occur in fdctrl_transfer_handler() in hw/block/fdcc while processing DMA read data transfers from the floppy drive to the guest system A privileged guest user could use this flaw to crash the QEMU process on the host resulting in a denial of service (DoS) scenario, or ...