6.5

CVE-2021-4145

A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qemu ≫ Qemu Version 6.1.0 Update -
Qemu ≫ Qemu Version 6.1.0 Update rc0
Qemu ≫ Qemu Version 6.1.0 Update rc1
Qemu ≫ Qemu Version 6.1.0 Update rc2
Qemu ≫ Qemu Version 6.1.0 Update rc3
Qemu ≫ Qemu Version 6.1.0 Update rc4
Redhat ≫ Enterprise Linux Version 8.0 SwEdition -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.306
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2 4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://security.gentoo.org/glsa/202208-27
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2034602
Patch
Third Party Advisory
Issue Tracking
https://gitlab.com/qemu-project/qemu/-/commit/66fed30c9cd11854fc878a4eceb507e915d7c9cd
Patch
Third Party Advisory
https://security.netapp.com/advisory/ntap-20220311-0004/
Third Party Advisory