Integer Overflow Flaw in QEMU's QXL Display Device Emulation
CVE-2021-4206

8.2HIGH

Key Information:

Vendor

Qemu

Status
Vendor
CVE Published:
29 April 2022

What is CVE-2021-4206?

A vulnerability exists in the QXL display device emulation of QEMU, specifically due to an integer overflow in the cursor_alloc() function. This can lead to the allocation of a smaller than intended cursor object and potentially result in a heap-based buffer overflow. A malicious privileged guest user can exploit this vulnerability to crash the QEMU process running on the host or may be able to execute arbitrary code in the context of the QEMU process, posing significant risks to system integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

QEMU qemu-kvm 7.0.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.