Vulnerability Name: | CVE-2021-4206 (CCN-225639) | ||||||||||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2022-03-28 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
Published: | 2022-03-28 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2022-09-23 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
Summary: | A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 8.2 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) 7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-190 CWE-120 CWE-131 CWE-120 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-4206 Source: CCN Type: Red Hat Bugzilla - Bug 2036998 (CVE-2021-4206) - CVE-2021-4206 QEMU: QXL: integer overflow in cursor_alloc() can lead to heap buffer overflow Source: MISC Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=2036998 Source: XF Type: UNKNOWN qemu-cve20214206-integer-overflow(225639) Source: CCN Type: QEMU GIT Repository ui/cursor: fix integer overflow in cursor_alloc (CVE-2021-4206) Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20220905 [SECURITY] [DLA 3099-1] qemu security update Source: GENTOO Type: Third Party Advisory GLSA-202208-27 Source: MISC Type: Exploit, Third Party Advisory https://starlabs.sg/advisories/21-4206/ Source: DEBIAN Type: Third Party Advisory DSA-5133 Source: CCN Type: Mend Vulnerability Database CVE-2021-4206 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||
BACK |