Vulnerabilities > CVE-2021-3608 - Access of Uninitialized Pointer vulnerability in multiple products

047910
CVSS 6.0 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH

Summary

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.

Vulnerable Configurations

Part Description Count
Application
Qemu
349
OS
Debian
1
OS
Fedoraproject
1

Common Weakness Enumeration (CWE)