CVE-2021-20196
Aliases:DEBIAN-CVE-2021-20196
Advisory lineage Upstream: 0 Downstream: 15
Modified
Published: 26 May 2021, 21:16
Last modified:03 Aug 2024, 17:30
Vulnerability Summary
Overall Risk (default)
medium
36/100 CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.48% LOW
0% probability +0.44%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
26 May 2021, 21:16
Published
Vulnerability first disclosed
03 Aug 2024, 17:30
Last Modified
Vulnerability information updated
Description
A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 0.48%• Percentile: 40%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- debian•qemu
< 1:5.2+dfsg-11+deb11u3 | < 1:6.2+dfsg-1 | < 1:6.2+dfsg-1 | < 1:6.2+dfsg-1
- debian•debian_linux
9.0 | 10.0
- qemu•qemu
5.2.0
References (6)
- https://bugs.launchpad.net/qemu/+bug/1912780
- https://www.openwall.com/lists/oss-security/2021/01/28/1
- https://security.netapp.com/advisory/ntap-20210708-0004/
- https://lists.debian.org/debian-lts-announce/2022/04/msg00002.html
- https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html
- https://security-tracker.debian.org/tracker/CVE-2021-20196