Back

HIGH

QEMU: pvrdma: use-after-free issue in pvrdma_exec_cmd()

Published Mar 29, 2022

Description

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.

Affected products

Remediation

Red Hat statement

The versions of `qemu-kvm` as shipped with Red Hat Enterprise Linux and RHEL Advanced Virtualization are not affected by this flaw, as they are not built with PVRDMA support.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Mar 29, 2022
Updated Aug 2, 2024
Reserved Mar 22, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Mar 21, 2022
Bugzilla 2069625

ENISA EUVD

Assigner redhat
Published Mar 29, 2022
Updated Aug 2, 2024

GitHub

No data