Integer Overflow Flaw in QEMU's QXL Display Device Emulation
CVE-2021-4206
8.2HIGH
What is CVE-2021-4206?
A vulnerability exists in the QXL display device emulation of QEMU, specifically due to an integer overflow in the cursor_alloc() function. This can lead to the allocation of a smaller than intended cursor object and potentially result in a heap-based buffer overflow. A malicious privileged guest user can exploit this vulnerability to crash the QEMU process running on the host or may be able to execute arbitrary code in the context of the QEMU process, posing significant risks to system integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
QEMU qemu-kvm 7.0.0
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
