CVE-2021-3638
Summary
| CVE | CVE-2021-3638 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-03 23:15:00 UTC |
| Updated | 2023-02-23 20:23:00 UTC |
| Description | An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 37 Update: qemu-7.0.0-12.fc37 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| CVE-2021-3638 QEMU Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [PATCH] hw/display/ati_2d: Fix buffer overflow in ati_2d_blt (CVE-2021-3 |
MISC |
lists.nongnu.org |
|
| CVE-2021-3638 | Ubuntu |
MISC |
ubuntu.com |
|
| 1979858 – (CVE-2021-3638) CVE-2021-3638 QEMU: ati-vga: inconsistent check in ati_2d_blt() may lead to out-of-bounds write |
MISC |
bugzilla.redhat.com |
|
| [SECURITY] Fedora 36 Update: qemu-6.2.0-17.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: qemu-7.0.0-12.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: qemu-6.2.0-17.fc36 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160408 Oracle Enterprise Linux Security Update for qemu (ELSA-2023-12065)
- 160453 Oracle Enterprise Linux Security Update for virt:kvm_utils (ELSA-2023-12108)
- 178817 Debian Security Update for qemu (DSA 4980-1)
- 183246 Debian Security Update for qemu (CVE-2021-3638)
- 283510 Fedora Security Update for qemu (FEDORA-2022-22b1f8dae2)
- 283617 Fedora Security Update for qemu (FEDORA-2023-c8a60f6f80)
- 754898 SUSE Enterprise Linux Security Update for qemu (SUSE-SU-2023:3721-1)
- 755084 SUSE Enterprise Linux Security Update for qemu (SUSE-SU-2023:4056-1)
- 755817 SUSE Enterprise Linux Security Update for qemu (SUSE-SU-2024:0589-1)
- 900747 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu-kvm (8957)
- 900989 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu (8975)
- 902022 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu-kvm (8957-1)
- 902114 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu (8975-1)