HomeQemuCVE-2021-4206

CVE-2021-4206

HIGH
8.2CVSS
Published: 2022-04-29
Updated: 2025-03-21
AI Analysis

Description

A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
local
Complexity
low
Privileges
high
User Action
none
Scope
changed
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-190CWE-120CWE-131CWE-190

Metadata

Primary Vendor
QEMU
Published
4/29/2022
Last Modified
3/21/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

qemu : qemuredhat : enterprise_linuxredhat : enterprise_linuxdebian : debian_linuxdebian : debian_linux

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2021-4206 | HIGH Severity | CVEDatabase.com | CVEDatabase.com