Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2021-3748 Details

Description

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://bugzilla.redhat.com/show_bug.cgi?id=1998514 CVEIssue TrackingPatchThird Party Advisory
https://github.com/qemu/qemu/commit/bedd7e93d01961fcb16a97ae45d93acf357e11f6 CVEPatchThird Party Advisory
https://lists.debian.org/debian-lts-announce/2022/04/msg00002.html CVEMailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html CVEMailing ListThird Party Advisory
https://lists.nongnu.org/archive/html/qemu-devel/2021-09/msg00388.html CVEMailing ListPatchThird Party Advisory

see all 16 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-416Use After Free[email protected]
CWE-416Use After Free[email protected]

Affected Products

ProductVersions

Change History

11 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2021-3748
NVD Published Date:
Mar 23, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2021-3748 Details - Not Deferred