CVE-2021-3713 - CVE House
Back to Database
Status published High CVE-2021-3713

An out-of-bounds write flaw was found in the UAS (USB...

Vulnerability Description

An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3713

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

QEMU
Vulnerable Versions:
qemu 6.2.0-rc0

Timeline

Official Publish: August 25th, 2021
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)