CVE-2021-3930 log

Source
Severity Low
Remote No
Type Denial of service
Description
An off-by-one error was found in the SCSI Device emulation in QEMU. It could occur in hw/scsi/scsi-disk.c:mode_sense_page() while processing MODE SELECT commands if 'page' was set to MODE_PAGE_ALLS (0x3f). Specifically, 'page' was used to index the stack-allocated 'mode_sense_valid' buffer (size=0x3f), causing an off-by-one error when trying to access the last element. A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
Group Package Affected Fixed Severity Status Ticket
AVG-1898 qemu 6.1.0-5 Medium Vulnerable
References
https://bugzilla.redhat.com/show_bug.cgi?id=2020588
https://bugs.launchpad.net/qemu/+bug/1914638
https://gitlab.com/qemu-project/qemu/-/issues/546
https://www.mail-archive.com/qemu-devel@nongnu.org/msg779652.html