CVE-2021-4206 - CVE House
Back to Database
Status published High CVE-2021-4206

A flaw was found in the QXL display device emulation...

Vulnerability Description

A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-4206

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

QEMU
Vulnerable Versions:
qemu-kvm 7.0.0

Timeline

Official Publish: April 29th, 2022
Last Modified: March 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)