CVE-2021-3607
Published: February 24, 2022Last modified: November 8, 2023
Description
An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 6 | 
| Attack Vector | LOCAL | 
| Attack complexity | LOW | 
| Privileges required | HIGH | 
| User interaction | NONE | 
| Scope | CHANGED | 
| Confidentiality | NONE | 
| Integrity impact | NONE | 
| Availability impact | HIGH | 
| Vector | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H | 
Status
| Product | Release | Package | Status | 
|---|---|---|---|
| Alpaquita Linux | 23 LTS | qemu | Not affected (7.1.0-r4) | 
| Stream | qemu | Not affected (8.0.4-r0) |