CVE-2021-3947
Summary
| CVE | CVE-2021-3947 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-18 18:15:00 UTC |
| Updated | 2023-11-21 21:38:00 UTC |
| Description | A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2021-3947 QEMU Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| 2021869 – (CVE-2021-3947) CVE-2021-3947 QEMU: NVME: Arbitrary Memory Read | MISC | bugzilla.redhat.com | |
| QEMU: Multiple Vulnerabilities (GLSA 202208-27) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159638 Oracle Enterprise Linux Security Update for qemu (ELSA-2022-9123)
- 159672 Oracle Enterprise Linux Security Update for kvm_utils (ELSA-2022-9172)
- 183954 Debian Security Update for qemu (CVE-2021-3947)
- 502168 Alpine Linux Security Update for qemu
- 710604 Gentoo Linux QEMU Multiple Vulnerabilities (GLSA 202208-27)
- 900709 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu-kvm (8688)
- 901146 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu (8672)
- 902083 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu (8672-1)
- 906027 Common Base Linux Mariner (CBL-Mariner) Security Update for qemu-kvm (8688-1)