vulnerability

Oracle Linux: CVE-2021-3611: ELSA-2022-7967: qemu-kvm security, bug fix, and enhancement update (MODERATE) (Multiple Advisories)

Severity
2
CVSS
(AV:L/AC:L/Au:S/C:N/I:N/A:P)
Published
2020-12-09
Added
2022-11-22
Modified
2025-01-07

Description

A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. This flaw affects QEMU versions prior to 7.0.0.
A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

Solution(s)

oracle-linux-upgrade-qemu-guest-agentoracle-linux-upgrade-qemu-imgoracle-linux-upgrade-qemu-kvmoracle-linux-upgrade-qemu-kvm-audio-paoracle-linux-upgrade-qemu-kvm-block-curloracle-linux-upgrade-qemu-kvm-block-rbdoracle-linux-upgrade-qemu-kvm-commonoracle-linux-upgrade-qemu-kvm-coreoracle-linux-upgrade-qemu-kvm-device-display-virtio-gpuoracle-linux-upgrade-qemu-kvm-device-display-virtio-gpu-gloracle-linux-upgrade-qemu-kvm-device-display-virtio-gpu-pcioracle-linux-upgrade-qemu-kvm-device-display-virtio-gpu-pci-gloracle-linux-upgrade-qemu-kvm-device-display-virtio-vgaoracle-linux-upgrade-qemu-kvm-device-display-virtio-vga-gloracle-linux-upgrade-qemu-kvm-device-usb-hostoracle-linux-upgrade-qemu-kvm-device-usb-redirectoracle-linux-upgrade-qemu-kvm-docsoracle-linux-upgrade-qemu-kvm-toolsoracle-linux-upgrade-qemu-kvm-ui-egl-headlessoracle-linux-upgrade-qemu-kvm-ui-opengloracle-linux-upgrade-qemu-pr-helper
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.