CVE-2021-20295
Summary
| CVE | CVE-2021-20295 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-01 23:15:00 UTC |
| Updated | 2022-10-06 02:32:00 UTC |
| Description | It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to include the fix for the qemu-kvm component issue CVE-2020-10756, which was previously corrected in virt:rhel/qemu-kvm via erratum RHSA-2020:4059 (https://access.redhat.com/errata/RHSA-2020:4059). CVE-2021-20295 was assigned to that Red Hat specific security regression. For more details about the original security issue CVE-2020-10756, refer to bug 1835986 or the CVE page: https://access.redhat.com/security/cve/CVE-2020-10756. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2021-20295 QEMU Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| 1944075 – (CVE-2021-20295) CVE-2021-20295 QEMU: Regression of CVE-2020-10756 fix in virt:rhel/qemu-kvm in Red Hat Enterprise Linux 8.3 | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159139 Oracle Enterprise Linux Security Update for virt:ol and virt-devel:rhel (ELSA-2021-1064)
- 239211 Red Hat Update for virt:rhel and virt-devel:rhel (RHSA-2021:1064)
- 900807 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu-kvm (9274)
- 905209 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu-kvm (9274-1)
- 905845 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu-kvm (9274-2)
- 940373 AlmaLinux Security Update for virt:rhel and virt-devel:rhel (ALSA-2021:1064)
- 960219 Rocky Linux Security Update for virt:rhel and virt-devel:rhel (RLSA-2021:1064)