4.4
CVSSv3

CVE-2021-3735

Published: 26/08/2022 Updated: 07/11/2023
CVSS v3 Base Score: 4.4 | Impact Score: 3.6 | Exploitability Score: 0.8
VMScore: 0

Vulnerability Summary

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu 6.1.0

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #1014767 qemu: CVE-2021-3735 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 11 Jul 2022 18:03:01 UTC Severity: normal Tags: security, upstream Reply or subscribe to this ...
A deadlock issue was found in the AHCI controller device of QEMU It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition T ...
A deadlock issue was found in the AHCI controller device (ich9-ahci) of QEMU while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest The bug is triggered on a software reset (ahci_reset_port) in the handle_reg_h2d_fis() function [1] A privileged user inside the guest could use this flaw to hang the QEMU pr ...