VDB

CVE-2021-3507

CVE-2021-3507 PUBLISHED

A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

EPSS 0.03% · 8.9th percentile

Risk Scores

EPSS Score
0.03%
8.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSqemu1.7.0+dfsg-2ubuntu8, 1.6.0+dfsg-2ubuntu3, 1.6.0+dfsg-2ubuntu4
Ubuntu:22.04:LTSqemu1:6.0+dfsg-2expubuntu2, 1:6.0+dfsg-2expubuntu4, 0
Ubuntu:18.04:LTSqemu*, 1:2.10+dfsg-0ubuntu3, 1:2.10+dfsg-0ubuntu4
Ubuntu:20.04:LTSqemu1:4.2-3ubuntu6.8, 1:4.2-3ubuntu6.10, 1:4.2-3ubuntu6.11
Ubuntu:Pro:16.04:LTSqemu1:2.5+dfsg-5ubuntu10.47, 1:2.5+dfsg-5ubuntu10.46, 1:2.5+dfsg-5ubuntu10.45

Timeline

  • Apr 19, 2021 CVE Published
  • May 7, 2021 EPSS Score
  • Jul 10, 2021 EPSS Score
  • Sep 10, 2021 EPSS Score
  • Nov 11, 2021 EPSS Score
  • Jan 11, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 14, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 15, 2022 EPSS Score
  • Jul 17, 2022 EPSS Score
  • Sep 17, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›