CVE-2021-3947
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
18/02/2022
Last modified:
21/11/2023
Description
A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | 6.0.0 (including) | 6.1.0 (including) |
| cpe:2.3:a:qemu:qemu:6.2.0:rc0:*:*:*:*:*:* | ||
| cpe:2.3:a:qemu:qemu:6.2.0:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



