CVE-2021-3947

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
18/02/2022
Last modified:
21/11/2023

Description

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* 6.0.0 (including) 6.1.0 (including)
cpe:2.3:a:qemu:qemu:6.2.0:rc0:*:*:*:*:*:*
cpe:2.3:a:qemu:qemu:6.2.0:rc1:*:*:*:*:*:*