Wind River Support Network

HomeDefectsLIN10-8204
Fixed

LIN10-8204 : Security Advisory - qemu - CVE-2021-20203

Created: Jan 31, 2021    Updated: Apr 1, 2021
Resolved Date: Apr 1, 2021
Found In Version: 10.17.41.1
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.

https://lists.gnu.org/archive/html/qemu-devel/2021-01/msg07935.html

CREATE(Triage):(User=admin) [CVE-2021-20203|https://nvd.nist.gov/vuln/detail/CVE-2021-20203]

CVEs


Live chat
Online