CVE-2021-20257
16.03.2022, 15:15
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Vendor | Product | Version |
---|---|---|
qemu | qemu | 𝑥 < 6.2.0 |
redhat | openstack_platform | 10.0 |
redhat | openstack_platform | 13.0 |
redhat | enterprise_linux | 6.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux_for_ibm_z_systems | 8.0 |
redhat | enterprise_linux_for_power_little_endian | 8.0 |
redhat | codeready_linux_builder | - |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
qemu |
| ||||||||||||||||||||||||
qemu-kvm |
|
Common Weakness Enumeration
References