VulnerabilityModified
CVE-2021-20203
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0.
LOW 3.2EPSS 0.59%
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
- CVSS 3.1
- 3.2 LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- qemu/qemu · fedoraproject/fedora · debian/debian linux
- Source
- secalert@redhat.com
References
- https://bugs.launchpad.net/qemu/+bug/1913873Exploit, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1922441Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00009.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202208-27Third Party Advisory
- https://bugs.launchpad.net/qemu/+bug/1913873Exploit, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1922441Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00009.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202208-27Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.