VDB

DEBIAN-CVE-2021-4145

DEBIAN-CVE-2021-4145 PUBLISHED CVSS 6.5 MEDIUM

A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:13qemu0, 0, 0
Debian:14qemu0, 0, 0
Debian:12qemu0, 0, 0

Timeline

  • Jan 25, 2022 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›