CVE-2021-20255

Aliases:UBUNTU-CVE-2021-20255DEBIAN-CVE-2021-20255CGA-22mp-94r9-fmxpCGA-2mg4-jrw7-4f64CGA-42fp-wf72-vpjjCGA-5fpf-rpxp-94f9CGA-64vj-jjfx-j82wCGA-7264-m8mc-6gh6CGA-7c62-64wm-38hjCGA-7g8x-rxj7-hj53CGA-7wv6-6hc7-mmpcCGA-7xc4-483j-wgc5CGA-8hhm-mfq4-99jmCGA-93r3-97q7-wh2gCGA-c7gr-r3jc-3rfpCGA-c8m4-6932-7w95CGA-cgfr-p3h9-hvg5CGA-chqp-cxrx-7mg4CGA-cx54-f9r8-5gqmCGA-f2mg-jp7j-rjx6CGA-fjwx-p698-qvq3CGA-h76f-7gm3-hf9hCGA-hf8f-gpf3-m28qCGA-jcp6-86v3-38v2CGA-mj8f-233q-rmqjCGA-mww5-f2mg-5j9xCGA-p85c-w494-86hvCGA-pm4j-3w34-g75pCGA-v6m5-7955-98x6CGA-x8cm-v265-4g9g
Modified
Published: 09 Mar 2021, 19:14
Last modified:03 Aug 2024, 17:37

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.41% LOW
0% probability +0.24%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Mar 2021, 19:14
Published
Vulnerability first disclosed
03 Aug 2024, 17:37
Last Modified
Vulnerability information updated

Description

A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.41% Percentile: 35%

Techniques & Countermeasures

  • CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')

    The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

  • CWE-674Uncontrolled Recursion

    The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Systems

  • chainguardqemu

    < 11.0.1-r0

  • chainguardqemu-block-iscsi

    < 11.0.1-r0

  • chainguardqemu-block-rbd

    < 11.0.1-r0

  • chainguardqemu-edk2-aarch64

    < 11.0.1-r0

  • chainguardqemu-edk2-x86_64

    < 11.0.1-r0

  • chainguardqemu-ipxe

    < 11.0.1-r0

  • chainguardqemu-modules

    < 11.0.1-r0

  • chainguardqemu-modules-spice

    < 11.0.1-r0

  • chainguardqemu-modules-usb-host

    < 11.0.1-r0

  • chainguardqemu-system-aarch64

    < 11.0.1-r0

  • chainguardqemu-system-x86_64

    < 11.0.1-r0

  • chainguardqemu-user

    < 11.0.1-r0

  • chainguardqemu-user-binfmt

    < 11.0.1-r0

  • chainguardqemu-utils

    < 11.0.1-r0

  • wolfiqemu

    < 11.0.1-r0

  • wolfiqemu-block-iscsi

    < 11.0.1-r0

  • wolfiqemu-block-rbd

    < 11.0.1-r0

  • wolfiqemu-edk2-aarch64

    < 11.0.1-r0

  • wolfiqemu-edk2-x86_64

    < 11.0.1-r0

  • wolfiqemu-ipxe

    < 11.0.1-r0

  • wolfiqemu-modules

    < 11.0.1-r0

  • wolfiqemu-modules-spice

    < 11.0.1-r0

  • wolfiqemu-modules-usb-host

    < 11.0.1-r0

  • wolfiqemu-system-aarch64

    < 11.0.1-r0

  • wolfiqemu-system-x86_64

    < 11.0.1-r0

  • wolfiqemu-user

    < 11.0.1-r0

  • wolfiqemu-user-binfmt

    < 11.0.1-r0

  • wolfiqemu-utils

    < 11.0.1-r0

  • debianqemu

    all | all | < 1:8.1.0+ds-1 | < 1:8.1.0+ds-1

  • ubuntuqemu

    all | all | all | all | all

  • ubuntuqemu-hwe

    all

  • debiandebian_linux

    9.0

References (9)