VDB
CVE-2021-4145
CVE-2021-4145
PUBLISHED
CVSS 8.699999809265137 HIGH
Es besteht eine Schwachstelle in QEMU aufgrund einer NULL-Zeiger-Dereferenz in "mirror_wait_on_conflicts()". Ein Angreifer von einer Gastmaschine aus kann dies durch das Schreiben sehr großer Dateien auslösen und so einen Denial of Service-Zustand herbeiführen.
EPSS 0.06% · 18.4th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.06%
18.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Broadcom Brocade Switch | |
| HPE | HPE Switch Fibre Channel | |
| Avaya | Avaya Aura Application Enablement Services | |
| HPE | HPE Switch SAN | |
| HPE | HPE Switch | |
| Open Source | Open Source QEMU | |
| Oracle | Oracle Linux | |
| Gentoo | Gentoo Linux | |
| Avaya | Avaya Aura Communication Manager | |
| Red Hat | Red Hat Enterprise Linux |
Timeline
- Dec 21, 2021 CVE Published
- Jan 26, 2022 EPSS Score
- Mar 17, 2022 CVE Updated
- Mar 20, 2022 EPSS Score
- May 12, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Aug 27, 2022 EPSS Score
- Oct 18, 2022 EPSS Score
- Dec 10, 2022 EPSS Score
- Feb 1, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 26, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2021/wid-sec-w-2022-1125.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-1125 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2034602 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2001404 advisory
- http://linux.oracle.com/errata/ELSA-2022-9344.html advisory
- https://access.redhat.com/errata/RHSA-2022:1759 advisory
- https://downloads.avaya.com/css/P8/documents/101081791 advisory
- https://security.gentoo.org/glsa/202208-27 advisory
- https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-hpesbst04494en_us advisory
- https://linux.oracle.com/errata/ELSA-2024-12604.html advisory
- https://linux.oracle.com/errata/ELSA-2024-12605.html advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1969.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1969 advisory