A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the 'Information Transfer' command (CMD_TI). This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service or potential code execution with the privileges of the QEMU process.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 22, 2024 | May 28, 2021 |
| Debian | — | Upgrade qemu | Jul 30, 2024 | May 28, 2021 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Aug 16, 2022 | May 28, 2021 |
| Suse | — | Upgrade qemu-ui-gtkUpgrade qemu-ppcUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-hw-usb-redirectUpgrade qemu-block-curlUpgrade qemu-chardev-baumUpgrade qemu-hw-usb-smartcardUpgrade qemu-kvmUpgrade qemu-seabiosUpgrade qemu-block-dmgUpgrade qemu-ui-spice-coreUpgrade qemu-audio-paUpgrade qemu-ui-cursesUpgrade qemu-guest-agentUpgrade qemu-linux-userUpgrade qemu-block-iscsiUpgrade qemu-extraUpgrade qemu-ksmUpgrade qemu-microvmUpgrade qemu-audio-alsaUpgrade qemu-s390Upgrade qemu-vgabiosUpgrade qemu-x86Upgrade qemu-testsuiteUpgrade qemu-langUpgrade qemu-ui-spice-appUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-chardev-spiceUpgrade qemu-ivshmem-toolsUpgrade qemu-block-nfsUpgrade qemu-audio-spiceUpgrade qemu-block-glusterUpgrade qemu-ipxeUpgrade qemu-vhost-user-gpuUpgrade qemu-toolsUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-sgabiosUpgrade qemuUpgrade qemu-block-rbdUpgrade qemu-audio-sdlUpgrade qemu-skibootUpgrade qemu-block-sshUpgrade qemu-hw-display-qxlUpgrade qemu-audio-ossUpgrade qemu-armUpgrade qemu-ui-openglUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-s390xUpgrade qemu-ui-sdl | Aug 21, 2021 | May 28, 2021 |
| Ubuntu | — | Upgrade qemu | Nov 19, 2024 | May 28, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub