A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 22, 2024 | May 28, 2021 |
| Debian | — | Upgrade qemu | Sep 6, 2022 | May 28, 2021 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Aug 16, 2022 | May 28, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade qemu-img | Jan 28, 2022 | May 28, 2021 |
| Suse | — | Upgrade qemu-block-nfsUpgrade qemu-audio-ossUpgrade qemu-linux-userUpgrade qemu-ivshmem-toolsUpgrade qemu-ui-openglUpgrade qemu-hw-display-qxlUpgrade qemu-skibootUpgrade qemu-armUpgrade qemu-block-dmgUpgrade qemu-ui-cursesUpgrade qemu-audio-paUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-ui-spice-appUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-x86Upgrade qemu-block-glusterUpgrade qemu-ppcUpgrade qemu-toolsUpgrade qemuUpgrade qemu-hw-usb-redirectUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-guest-agentUpgrade qemu-extraUpgrade qemu-hw-usb-smartcardUpgrade qemu-ui-sdlUpgrade qemu-sgabiosUpgrade qemu-s390xUpgrade qemu-vgabiosUpgrade qemu-seabiosUpgrade qemu-chardev-baumUpgrade qemu-audio-spiceUpgrade qemu-block-curlUpgrade qemu-testsuiteUpgrade qemu-microvmUpgrade qemu-audio-sdlUpgrade qemu-vhost-user-gpuUpgrade qemu-block-iscsiUpgrade qemu-kvmUpgrade qemu-s390Upgrade qemu-ui-gtkUpgrade qemu-ui-spice-coreUpgrade qemu-ipxeUpgrade qemu-audio-alsaUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-chardev-spiceUpgrade qemu-block-rbdUpgrade qemu-langUpgrade qemu-ksmUpgrade qemu-block-ssh | Aug 21, 2021 | May 28, 2021 |
| Ubuntu | — | Upgrade qemu-user-static (Ubuntu Pro)Upgrade qemu-system-ppcUpgrade qemu (Ubuntu Pro)Upgrade qemu-system-ppc (Ubuntu Pro)Upgrade qemu-system (Ubuntu Pro)Upgrade qemu-system-armUpgrade qemu-system-s390x (Ubuntu Pro)Upgrade qemu-user-binfmt (Ubuntu Pro)Upgrade qemu-system-s390xUpgrade qemu-keymaps (Ubuntu Pro)Upgrade qemu-system-arm (Ubuntu Pro)Upgrade qemu-systemUpgrade qemu-user (Ubuntu Pro)Upgrade qemu-system-x86-xenUpgrade qemu-system-misc (Ubuntu Pro)Upgrade qemu-system-x86-microvmUpgrade qemu-guest-agent (Ubuntu Pro)Upgrade qemu-system-x86 (Ubuntu Pro)Upgrade qemu-system-sparcUpgrade qemu-system-sparc (Ubuntu Pro)Upgrade qemu-system-mips (Ubuntu Pro)Upgrade qemu-block-extra (Ubuntu Pro)Upgrade qemu-kvm (Ubuntu Pro)Upgrade qemu-system-miscUpgrade qemu-common (Ubuntu Pro)Upgrade qemu-system-common (Ubuntu Pro)Upgrade qemu-system-x86Upgrade qemu-utils (Ubuntu Pro)Upgrade qemu-system-aarch64 (Ubuntu Pro)Upgrade qemu-system-mips | Jul 16, 2021 | May 28, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub