{"schema_version":"1.7.5","id":"CVE-2021-20255","published":"2021-03-09T20:15:13.133Z","modified":"2026-07-09T00:07:23.472688Z","related":["CGA-rcqm-hp8r-w5g8","SUSE-SU-2021:14848-1","SUSE-SU-2021:2789-1","SUSE-SU-2021:2813-1","SUSE-SU-2021:2858-1","SUSE-SU-2021:2924-1","SUSE-SU-2021:2955-1","SUSE-SU-2021:2957-1","SUSE-SU-2021:3322-1","SUSE-SU-2021:3575-1","SUSE-SU-2021:3613-1","SUSE-SU-2021:3614-1","SUSE-SU-2021:3635-1","openSUSE-SU-2021:1202-1","openSUSE-SU-2021:2789-1","openSUSE-SU-2021:2858-1","openSUSE-SU-2021:3614-1"],"details":"A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qemu/qemu","events":[{"introduced":"c25df57ae8f9fe1c72eee2dab37d76d904ac382e"},{"last_affected":"c25df57ae8f9fe1c72eee2dab37d76d904ac382e"}],"database_specific":{"cpe":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING"}}],"versions":["9.0","v9.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20255.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/04/msg00009.html"},{"type":"ADVISORY","url":"https://ruhr-uni-bochum.sciebo.de/s/NNWP2GfwzYKeKwE?path=%2Feepro100_stackoverflow1"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210507-0003/"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1930646"},{"type":"FIX","url":"https://www.openwall.com/lists/oss-security/2021/02/25/1"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}