CVE-2021-3392

A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.2 LOW
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
qemuqemu
2.10.0 ≤
𝑥
≤ 5.2.0
debiandebian_linux
9.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
qemu
bookworm
1:7.2+dfsg-7+deb12u7
fixed
bullseye
1:5.2+dfsg-11+deb11u3
fixed
bullseye (security)
1:5.2+dfsg-11+deb11u2
fixed
sid
1:9.1.1+ds-2
fixed
trixie
1:9.1.1+ds-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qemu
bionic
Fixed 1:2.11+dfsg-1ubuntu7.37
released
focal
Fixed 1:4.2-3ubuntu6.17
released
groovy
Fixed 1:5.0-5ubuntu9.9
released
hirsute
Fixed 1:5.2+dfsg-9ubuntu3.1
released
impish
Fixed 1:6.0+dfsg-1~ubuntu3
released
jammy
Fixed 1:6.0+dfsg-1~ubuntu3
released
kinetic
Fixed 1:6.0+dfsg-1~ubuntu3
released
lunar
Fixed 1:6.0+dfsg-1~ubuntu3
released
mantic
Fixed 1:6.0+dfsg-1~ubuntu3
released
noble
Fixed 1:6.0+dfsg-1~ubuntu3
released
trusty
needed
xenial
needed
qemu-kvm
bionic
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
ivshmem-tools
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-audio-alsa
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-audio-oss
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-audio-pa
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-audio-sdl
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-block-curl
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-block-dmg
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-block-iscsi
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-block-nfs
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-block-rbd
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-block-ssh
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-common
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-debuginfo
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-guest-agent
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-img
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-kvm
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-kvm-core
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-system-aarch64
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-system-aarch64-core
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-system-x86
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-system-x86-core
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-ui-curses
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-ui-gtk
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-ui-sdl
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-user
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-user-binfmt
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
qemu-user-static
Amazon Linux 2
10:3.1.0-8.amzn2.0.10
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
qemu-kvm
CBL-Mariner 1.0
0:4.2.0-29.cm1
fixed