← volver
CVE-2021-3682CWE-763

CVE-2021-3682

3Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackepss 2.9%
probabilidad de explotación
2.9%top 14% de las CVE
explotación observada
noninguna fuente lo reporta
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
Productos afectados
n/a · QEMU