Description
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.
Solution(s)
huawei-euleros-2_0_sp9-upgrade-qemu-img
Referenceshttps://attackerkb.com/topics/cve-2021-3748CVE - 2021-3748EulerOS-SA-2022-1034