Wind River Support Network

HomeDefectsLIN1021-678
Fixed

LIN1021-678 : Security Advisory - qemu - CVE-2021-3608

Created: Jun 20, 2021    Updated: Mar 7, 2022
Resolved Date: Sep 27, 2021
Found In Version: 10.21.20.1
Fix Version: 10.21.20.6
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The flaw exists in the pvrdma_ring_init() function in hw/rdma/vmw/pvrdma_dev_ring.c and could occur while handling a "PVRDMA_REG_DSRHIGH" write from the guest. Due to improper initialization of the 'ring->pages' array, rdma_pci_dma_unmap() may be passed an uninitialized pointer as argument, leading to undefined behavior and possible crash of the QEMU process on the host.


CREATE(Triage):(User=admin) CVE-2021-3608 (https://nvd.nist.gov/vuln/detail/CVE-2021-3608)

CVEs


Live chat
Online