Back to search
CVE-2021-3545
Published: Jun 2, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized memory. A malicious guest could exploit this issue to leak memory from the host.
| Vendor | Product | Versions |
|---|---|---|
n/a | QEMU | affected All QEMU versions up to and including 6.0 |
Weaknesses (CWE)
References
[oss-security] 20210531 QEMU: security issues in vhost-user-gpu
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=1958955
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20210720-0008/
x_refsource_CONFIRM
DSA-4980
vendor-advisory
x_refsource_DEBIAN
GLSA-202208-27
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now