Saturday, January 29, 2022

Huawei EulerOS: CVE-2021-3748: qemu security update

Description
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.
Solution(s)
  • huawei-euleros-2_0_sp9-upgrade-qemu-img


  • References
  • https://attackerkb.com/topics/cve-2021-3748
  • CVE - 2021-3748
  • EulerOS-SA-2022-1034




  •  

    Copyright © 2021 Vulnerability Database | Cyber Details™

    thank you Templateism for the design - You should have written the code a little more complicated - Nothing Encrypted anymore