[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2021-3748":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T20:55:29.923Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":66,"related":67,"reserved_at":9,"published_at":80,"modified_at":81,"state":82,"summary":83,"references_raw":92,"kevs":135,"epss":136,"epss_history":139,"metrics":408,"affected":418},"CVE-2021-3748","A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","weakness","Stable","Variant","High",[],[],[],[],[24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64],{"_key":25},"SUSE-SU-2021:3605-1",{"_key":27},"RHSA-2021:4112",{"_key":29},"RHSA-2021:5036",{"_key":31},"RHSA-2022:1759",{"_key":33},"OPENSUSE-SU-2021:3604-1",{"_key":35},"SUSE-SU-2021:3519-1",{"_key":37},"SUSE-SU-2021:3604-1",{"_key":39},"SUSE-SU-2021:3613-1",{"_key":41},"SUSE-SU-2021:3614-1",{"_key":43},"SUSE-SU-2021:3635-1",{"_key":45},"SUSE-SU-2021:3653-1",{"_key":47},"UBUNTU-CVE-2021-3748",{"_key":49},"OPENSUSE-SU-2021:1461-1",{"_key":51},"OPENSUSE-SU-2021:3605-1",{"_key":53},"OPENSUSE-SU-2021:3614-1",{"_key":55},"OPENSUSE-SU-2024:11597-1",{"_key":57},"DLA-2970-1",{"_key":59},"DLA-3099-1",{"_key":61},"DSA-4980-1",{"_key":63},"USN-5307-1",{"_key":65},"DEBIAN-CVE-2021-3748",[],[68,69,70,71,72,73,74,75,76,77,78,79],{"_key":25},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":49},{"_key":51},{"_key":53},{"_key":55},"2022-03-23T19:46:40.000Z","2024-08-03T17:09:08.293Z","Modified",{"cisa_kev":84,"cisa_ransomware":84,"cisa_vendor":9,"epss_severity":85,"epss_score":86,"severity":87,"severity_score":88,"severity_version":89,"severity_source":90,"severity_vector":91,"severity_status":82},false,"low",0.00035,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",[93,102,106,110,115,120,125,131],{"url":94,"sources":95,"tags":97},"https://bugzilla.redhat.com/show_bug.cgi?id=1998514",[96,90],"cve.org",[98,99,100,101],"X Refsource MISC","Issue Tracking","Patch","Third Party Advisory",{"url":103,"sources":104,"tags":105},"https://ubuntu.com/security/CVE-2021-3748",[96,90],[98,100,101],{"url":107,"sources":108,"tags":109},"https://github.com/qemu/qemu/commit/bedd7e93d01961fcb16a97ae45d93acf357e11f6",[96,90],[98,100,101],{"url":111,"sources":112,"tags":113},"https://lists.nongnu.org/archive/html/qemu-devel/2021-09/msg00388.html",[96,90],[98,114,100,101],"Mailing List",{"url":116,"sources":117,"tags":118},"https://lists.debian.org/debian-lts-announce/2022/04/msg00002.html",[96,90],[114,119,101],"X Refsource MLIST",{"url":121,"sources":122,"tags":123},"https://security.netapp.com/advisory/ntap-20220425-0004/",[96,90],[124,101],"X Refsource CONFIRM",{"url":126,"sources":127,"tags":128},"https://security.gentoo.org/glsa/202208-27",[96,90],[129,130,101],"Vendor Advisory","X Refsource GENTOO",{"url":132,"sources":133,"tags":134},"https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html",[96,90],[114,119,101],[],{"date":137,"score":86,"percentile":138},"2026-06-04",0.10815,[140,144,147,150,153,156,159,162,165,168,171,174,177,180,182,186,189,192,195,198,201,204,207,210,212,215,218,220,224,228,231,234,237,240,242,245,248,251,254,257,260,263,266,269,272,275,278,281,284,287,290,293,296,299,303,307,310,313,316,319,322,325,328,331,334,337,339,341,344,347,351,354,357,360,363,366,369,372,375,377,380,383,385,387,390,393,396,399,402,405],{"date":141,"score":142,"percentile":143},"2025-11-04",0.00028,0.06413,{"date":145,"score":142,"percentile":146},"2025-11-05",0.06438,{"date":148,"score":142,"percentile":149},"2025-11-06",0.06549,{"date":151,"score":142,"percentile":152},"2025-11-07",0.06559,{"date":154,"score":142,"percentile":155},"2025-11-08",0.06555,{"date":157,"score":142,"percentile":158},"2025-11-09",0.06537,{"date":160,"score":142,"percentile":161},"2025-11-10",0.06513,{"date":163,"score":142,"percentile":164},"2025-11-11",0.06539,{"date":166,"score":142,"percentile":167},"2025-11-12",0.06579,{"date":169,"score":142,"percentile":170},"2025-11-13",0.06615,{"date":172,"score":142,"percentile":173},"2025-11-14",0.06641,{"date":175,"score":142,"percentile":176},"2025-11-15",0.06671,{"date":178,"score":142,"percentile":179},"2025-11-16",0.06682,{"date":181,"score":142,"percentile":179},"2025-11-17",{"date":183,"score":184,"percentile":185},"2025-11-18",0.00097,0.23122,{"date":187,"score":184,"percentile":188},"2025-11-19",0.23135,{"date":190,"score":184,"percentile":191},"2025-11-20",0.23138,{"date":193,"score":142,"percentile":194},"2025-11-21",0.06807,{"date":196,"score":142,"percentile":197},"2025-11-22",0.0679,{"date":199,"score":142,"percentile":200},"2025-11-23",0.06774,{"date":202,"score":142,"percentile":203},"2025-11-24",0.06754,{"date":205,"score":142,"percentile":206},"2025-11-25",0.06755,{"date":208,"score":142,"percentile":209},"2025-11-26",0.06757,{"date":211,"score":142,"percentile":203},"2025-11-27",{"date":213,"score":142,"percentile":214},"2025-11-28",0.06742,{"date":216,"score":142,"percentile":217},"2025-11-29",0.06781,{"date":219,"score":142,"percentile":217},"2025-11-30",{"date":221,"score":222,"percentile":223},"2025-12-01",0.00021,0.04792,{"date":225,"score":226,"percentile":227},"2025-12-02",0.00029,0.07522,{"date":229,"score":226,"percentile":230},"2025-12-03",0.07542,{"date":232,"score":226,"percentile":233},"2025-12-04",0.07529,{"date":235,"score":226,"percentile":236},"2025-12-05",0.07578,{"date":238,"score":226,"percentile":239},"2025-12-06",0.07591,{"date":241,"score":226,"percentile":239},"2025-12-07",{"date":243,"score":226,"percentile":244},"2025-12-08",0.07603,{"date":246,"score":226,"percentile":247},"2025-12-09",0.07655,{"date":249,"score":226,"percentile":250},"2025-12-10",0.07722,{"date":252,"score":226,"percentile":253},"2025-12-11",0.07767,{"date":255,"score":226,"percentile":256},"2025-12-12",0.0778,{"date":258,"score":226,"percentile":259},"2025-12-13",0.07749,{"date":261,"score":226,"percentile":262},"2025-12-14",0.07731,{"date":264,"score":226,"percentile":265},"2025-12-15",0.07674,{"date":267,"score":226,"percentile":268},"2025-12-16",0.07705,{"date":270,"score":226,"percentile":271},"2025-12-17",0.07788,{"date":273,"score":226,"percentile":274},"2025-12-18",0.07851,{"date":276,"score":226,"percentile":277},"2025-12-19",0.07843,{"date":279,"score":226,"percentile":280},"2025-12-20",0.07835,{"date":282,"score":226,"percentile":283},"2025-12-21",0.07806,{"date":285,"score":226,"percentile":286},"2025-12-22",0.07758,{"date":288,"score":226,"percentile":289},"2025-12-23",0.07764,{"date":291,"score":226,"percentile":292},"2025-12-24",0.07782,{"date":294,"score":226,"percentile":295},"2025-12-25",0.07859,{"date":297,"score":226,"percentile":298},"2025-12-26",0.07867,{"date":300,"score":301,"percentile":302},"2025-12-27",0.00031,0.08603,{"date":304,"score":305,"percentile":306},"2025-12-28",0.00023,0.05443,{"date":308,"score":305,"percentile":309},"2025-12-29",0.05437,{"date":311,"score":305,"percentile":312},"2025-12-30",0.05397,{"date":314,"score":305,"percentile":315},"2025-12-31",0.05432,{"date":317,"score":305,"percentile":318},"2026-01-01",0.05515,{"date":320,"score":305,"percentile":321},"2026-01-02",0.0551,{"date":323,"score":305,"percentile":324},"2026-01-03",0.05472,{"date":326,"score":305,"percentile":327},"2026-01-04",0.0537,{"date":329,"score":305,"percentile":330},"2026-01-05",0.0532,{"date":332,"score":305,"percentile":333},"2026-01-06",0.05316,{"date":335,"score":305,"percentile":336},"2026-01-07",0.05337,{"date":338,"score":305,"percentile":312},"2026-01-08",{"date":340,"score":305,"percentile":312},"2026-01-09",{"date":342,"score":305,"percentile":343},"2026-01-10",0.05402,{"date":345,"score":305,"percentile":346},"2026-01-11",0.05386,{"date":348,"score":349,"percentile":350},"2026-01-12",0.00026,0.06658,{"date":352,"score":349,"percentile":353},"2026-01-13",0.06644,{"date":355,"score":349,"percentile":356},"2026-01-14",0.06764,{"date":358,"score":349,"percentile":359},"2026-01-15",0.06767,{"date":361,"score":349,"percentile":362},"2026-01-16",0.06779,{"date":364,"score":349,"percentile":365},"2026-01-17",0.06794,{"date":367,"score":349,"percentile":368},"2026-01-18",0.06771,{"date":370,"score":349,"percentile":371},"2026-01-19",0.06725,{"date":373,"score":349,"percentile":374},"2026-01-20",0.06686,{"date":376,"score":349,"percentile":374},"2026-01-21",{"date":378,"score":349,"percentile":379},"2026-01-22",0.06663,{"date":381,"score":349,"percentile":382},"2026-01-23",0.06731,{"date":384,"score":349,"percentile":200},"2026-01-24",{"date":386,"score":349,"percentile":203},"2026-01-25",{"date":388,"score":349,"percentile":389},"2026-01-26",0.06739,{"date":391,"score":349,"percentile":392},"2026-01-27",0.06727,{"date":394,"score":349,"percentile":395},"2026-01-28",0.06702,{"date":397,"score":349,"percentile":398},"2026-01-29",0.067,{"date":400,"score":349,"percentile":401},"2026-01-30",0.06716,{"date":403,"score":349,"percentile":404},"2026-01-31",0.06738,{"date":406,"score":349,"percentile":407},"2026-02-01",0.06778,[409],{"source":90,"cvss_v2_0":410,"cvss_v3_0":9,"cvss_v3_1":415,"cvss_v4_0":9},{"baseScore":411,"baseSeverity":9,"vectorString":412,"impactScore":413,"exploitabilityScore":414},6.9,"AV:L/AC:M/Au:N/C:C/I:C/A:C",10,3.4,{"baseScore":88,"baseSeverity":416,"vectorString":91,"impactScore":413,"exploitabilityScore":417},"HIGH",2.1,[419,432,441,447,458,465],{"ecosystem":9,"name":420,"vendor":421,"product":422,"cpe_part":423,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":424},"ubuntu linux","canonical","ubuntu_linux","o",[425,428,430],{"version":426,"is_range":84,"range_type":427,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"18.04","cpe",{"version":429,"is_range":84,"range_type":427,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"20.04",{"version":431,"is_range":84,"range_type":427,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"21.10",{"ecosystem":9,"name":433,"vendor":434,"product":435,"cpe_part":423,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":436},"debian linux","debian","debian_linux",[437,439],{"version":438,"is_range":84,"range_type":427,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"9.0",{"version":440,"is_range":84,"range_type":427,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.0",{"ecosystem":9,"name":442,"vendor":443,"product":442,"cpe_part":423,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":444},"fedora","fedoraproject",[445],{"version":446,"is_range":84,"range_type":427,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"34",{"ecosystem":9,"name":448,"vendor":448,"product":448,"cpe_part":449,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":450},"qemu","a",[451],{"version":452,"is_range":453,"range_type":427,"version_start":454,"version_start_type":455,"version_end":456,"version_end_type":457,"fixed_in":9},"gte0.10.0_lt6.2.0",true,"0.10.0","including","6.2.0","excluding",{"ecosystem":9,"name":459,"vendor":460,"product":461,"cpe_part":423,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":462},"enterprise linux","redhat","enterprise_linux",[463],{"version":464,"is_range":84,"range_type":427,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.0",{"ecosystem":9,"name":466,"vendor":460,"product":467,"cpe_part":423,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":468},"enterprise linux advanced virtualization eus","enterprise_linux_advanced_virtualization_eus",[469],{"version":470,"is_range":84,"range_type":427,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.4"]