A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
CVSS Details
- CVSS 3.1 Base Score: 6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 22, 2024 | May 28, 2021 |
| Debian | — | Upgrade qemu | Sep 6, 2022 | May 28, 2021 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Aug 16, 2022 | May 28, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade qemu-img | Jan 28, 2022 | May 28, 2021 |
| Suse | — | Upgrade qemu-skibootUpgrade qemu-langUpgrade qemu-guest-agentUpgrade qemu-s390xUpgrade qemu-ipxeUpgrade qemu-block-rbdUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-ui-spice-coreUpgrade qemu-ppcUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-ui-gtkUpgrade qemu-ui-spice-appUpgrade qemu-audio-ossUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-chardev-spiceUpgrade qemu-block-curlUpgrade qemu-armUpgrade qemu-vhost-user-gpuUpgrade qemu-testsuiteUpgrade qemu-block-iscsiUpgrade qemu-audio-spiceUpgrade qemu-audio-sdlUpgrade qemu-ui-openglUpgrade qemu-audio-alsaUpgrade qemu-seabiosUpgrade qemu-ivshmem-toolsUpgrade qemu-block-sshUpgrade qemu-ksmUpgrade qemu-x86Upgrade qemu-hw-display-virtio-gpuUpgrade qemu-sgabiosUpgrade qemu-block-dmgUpgrade qemu-ui-sdlUpgrade qemu-ui-cursesUpgrade qemu-block-nfsUpgrade qemu-vgabiosUpgrade qemu-chardev-baumUpgrade qemu-microvmUpgrade qemu-audio-paUpgrade qemu-linux-userUpgrade qemu-hw-display-qxlUpgrade qemu-s390Upgrade qemu-block-glusterUpgrade qemu-hw-usb-redirectUpgrade qemu-extraUpgrade qemu-toolsUpgrade qemu-kvmUpgrade qemu-hw-usb-smartcardUpgrade qemu | Aug 21, 2021 | May 28, 2021 |
| Ubuntu | — | Upgrade qemu-system-mipsUpgrade qemu (Ubuntu Pro)Upgrade qemu-systemUpgrade qemu-system-ppcUpgrade qemu-system-ppc (Ubuntu Pro)Upgrade qemu-system-x86 (Ubuntu Pro)Upgrade qemu-system-misc (Ubuntu Pro)Upgrade qemu-user-static (Ubuntu Pro)Upgrade qemu-block-extra (Ubuntu Pro)Upgrade qemu-system-x86-microvmUpgrade qemu-system-sparc (Ubuntu Pro)Upgrade qemu-system-x86-xenUpgrade qemu-system-arm (Ubuntu Pro)Upgrade qemu-system-aarch64 (Ubuntu Pro)Upgrade qemu-common (Ubuntu Pro)Upgrade qemu-kvm (Ubuntu Pro)Upgrade qemu-system-s390x (Ubuntu Pro)Upgrade qemu-system-s390xUpgrade qemu-keymaps (Ubuntu Pro)Upgrade qemu-system-common (Ubuntu Pro)Upgrade qemu-system-sparcUpgrade qemu-user (Ubuntu Pro)Upgrade qemu-system-miscUpgrade qemu-system-armUpgrade qemu-guest-agent (Ubuntu Pro)Upgrade qemu-system-x86Upgrade qemu-utils (Ubuntu Pro)Upgrade qemu-user-binfmt (Ubuntu Pro)Upgrade qemu-system-mips (Ubuntu Pro)Upgrade qemu-system (Ubuntu Pro) | Jul 16, 2021 | May 28, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub