Search CVE reports


Toggle filters

61 – 70 of 470 results


CVE-2021-3611

Low priority

Some fixes available 5 of 8

A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat...

1 affected package

qemu

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Fixed Not affected Not affected
Show less packages

CVE-2021-3608

Low priority
Fixed

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause...

1 affected package

qemu

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Fixed Not affected
Show less packages

CVE-2021-3607

Low priority
Fixed

An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation....

1 affected package

qemu

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Fixed Not affected
Show less packages

CVE-2021-3595

Low priority
Fixed

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the...

2 affected packages

libslirp, qemu

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp Fixed Fixed Fixed Not in release
qemu Not affected Not affected Not affected Fixed
Show less packages

CVE-2021-3594

Low priority
Fixed

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the...

2 affected packages

libslirp, qemu

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp Fixed Fixed Fixed Not in release
qemu Not affected Not affected Not affected Fixed
Show less packages

CVE-2021-3593

Low priority

Some fixes available 12 of 14

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the...

2 affected packages

libslirp, qemu

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp Fixed Fixed Fixed Not in release
qemu Not affected Not affected Not affected Fixed
Show less packages

CVE-2021-3592

Low priority
Fixed

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the...

2 affected packages

qemu, libslirp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Not affected Not affected Not affected Fixed
libslirp Fixed Fixed Fixed Not in release
Show less packages

CVE-2021-3582

Medium priority
Fixed

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to improper memory remapping (mremap). This flaw allows a malicious guest to...

1 affected package

qemu

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Fixed Not affected
Show less packages

CVE-2021-3546

Medium priority
Fixed

An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw occurs while processing the 'VIRTIO_GPU_CMD_GET_CAPSET' command from the...

2 affected packages

qemu, qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Fixed Not affected
qemu-kvm Not in release Not in release Not in release
Show less packages

CVE-2021-3545

Low priority
Fixed

An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c...

2 affected packages

qemu, qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Fixed Not affected
qemu-kvm Not in release Not in release Not in release
Show less packages