Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-4158


A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.


Published

2022-08-24T16:15:09.660

Last Modified

2024-11-21T06:37:01.980

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.0 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-476
  • Type: Secondary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qemu qemu < 7.0.0 Yes
Operating System redhat enterprise_linux 9.0 Yes

References