CVE-2021-20255 PUBLISHED

A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

EPSS 0.17% · 37.7th percentile

Risk Scores

EPSS Score
0.17%
37.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSqemu1:4.0+dfsg-0ubuntu9, 0, *
Ubuntu:Pro:16.04:LTSqemu1:2.5+dfsg-5ubuntu10.34, *, *
Ubuntu:25.10qemu*, 0, 1:9.2.1+ds-1ubuntu5
Ubuntu:24.04:LTSqemu*, *, *
Ubuntu:22.04:LTSqemu*, *, *
Ubuntu:Pro:14.04:LTSqemu1.7.0+dfsg-3ubuntu4, *, 1.7.0+dfsg-3ubuntu1
Ubuntu:Pro:18.04:LTSqemu1:2.11+dfsg-1ubuntu7.41, 1:2.11+dfsg-1ubuntu7.40, 1:2.11+dfsg-1ubuntu7.39

Timeline

References

Open in Interactive Console →