DEBIAN-CVE-2021-20221
Advisory lineage Upstream: 1 Downstream: 2
Upstream
Downstream
Published: 13 May 2021, 16:15
Last modified:28 Apr 2026, 20:21
Vulnerability Summary
Overall Risk (default)
low
24/100 CVSS Score
6 MEDIUM
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
13 May 2021, 16:15
Published
Vulnerability first disclosed
28 Apr 2026, 20:21
Last Modified
Vulnerability information updated
Description
An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields and their subsequent processing. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
CVSS Metrics
- v3.1•MEDIUM•Score: 6CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Affected Systems
- debian•qemu
< 1:5.2+dfsg-4 | < 1:5.2+dfsg-4 | < 1:5.2+dfsg-4 | < 1:5.2+dfsg-4