DEBIAN-CVE-2021-20221

Advisory lineage Upstream: 1 Downstream: 2
Published: 13 May 2021, 16:15
Last modified:28 Apr 2026, 20:21

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
6 MEDIUM
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 May 2021, 16:15
Published
Vulnerability first disclosed
28 Apr 2026, 20:21
Last Modified
Vulnerability information updated

Description

An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields and their subsequent processing. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.

CVSS Metrics

  • v3.1MEDIUMScore: 6CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Affected Systems

  • debianqemu

    < 1:5.2+dfsg-4 | < 1:5.2+dfsg-4 | < 1:5.2+dfsg-4 | < 1:5.2+dfsg-4

References (1)