Description
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized memory. A malicious guest could exploit this issue to leak memory from the host.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4980-1 | qemu security update |
EUVD |
EUVD-2021-26856 | An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized memory. A malicious guest could exploit this issue to leak memory from the host. |
Ubuntu USN |
USN-5010-1 | QEMU vulnerabilities |
Ubuntu USN |
USN-5307-1 | QEMU vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:06.578Z
Reserved: 2021-05-10T00:00:00.000Z
Link: CVE-2021-3545
No data.
Status : Modified
Published: 2021-06-02T14:15:10.587
Modified: 2024-11-21T06:21:48.483
Link: CVE-2021-3545
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN