Back

MEDIUM

QEMU: pvrdma: unchecked malloc size due to integer overflow in init_dev_ring()

Published Feb 24, 2022

Description

An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Affected products

Remediation

Red Hat statement

The versions of `qemu-kvm` as shipped with Red Hat Enterprise Linux and RHEL Advanced Virtualization are not affected by this flaw, as they are not built with PVRDMA support.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 24, 2022
Updated Aug 3, 2024
Reserved Jun 17, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 17, 2021
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a