CVE-2021-3929
Summary
| CVE | CVE-2021-3929 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-25 20:15:00 UTC |
| Updated | 2023-11-07 03:38:00 UTC |
| Description | A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 2020298 – (CVE-2021-3929) CVE-2021-3929 QEMU: nvme: DMA reentrancy issue leads to use-after-free |
MISC |
bugzilla.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| nvme: DMA reentrancy issue leads to use-after-free (CVE-2021-3929) (#782) · Issues · QEMU / QEMU · GitLab |
MISC |
gitlab.com |
|
| hw/nvme: fix CVE-2021-3929 (736b0164) · Commits · QEMU / QEMU · GitLab |
MISC |
gitlab.com |
|
| Fix DMA MMIO reentrancy issues (#556) · Issues · QEMU / QEMU · GitLab |
MISC |
gitlab.com |
|
| [SECURITY] Fedora 36 Update: qemu-6.2.0-15.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: qemu-6.2.0-15.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182950 Debian Security Update for qemu (CVE-2021-3929)
- 198837 Ubuntu Security Notification for QEMU Vulnerabilities (USN-5489-1)
- 283141 Fedora Security Update for qemu (FEDORA-2022-f0a2695054)
- 710604 Gentoo Linux QEMU Multiple Vulnerabilities (GLSA 202208-27)
- 753802 SUSE Enterprise Linux Security Update for qemu (SUSE-SU-2023:0761-1)
- 753824 SUSE Enterprise Linux Security Update for qemu (SUSE-SU-2023:0840-1)
- 754898 SUSE Enterprise Linux Security Update for qemu (SUSE-SU-2023:3721-1)
- 754937 SUSE Enterprise Linux Security Update for qemu (SUSE-SU-2023:3800-1)
- 903787 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu-kvm (10725)
- 903830 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu (10721)
- 905240 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu (10721-1)