{"schema_version":"1.7.5","id":"CVE-2021-3748","published":"2022-03-23T20:15:09.893Z","modified":"2026-07-09T01:07:07.038707Z","related":["ALSA-2022:1759","SUSE-SU-2021:3519-1","SUSE-SU-2021:3604-1","SUSE-SU-2021:3605-1","SUSE-SU-2021:3613-1","SUSE-SU-2021:3614-1","SUSE-SU-2021:3635-1","SUSE-SU-2021:3653-1","openSUSE-SU-2021:1461-1","openSUSE-SU-2021:3604-1","openSUSE-SU-2021:3605-1","openSUSE-SU-2021:3614-1","openSUSE-SU-2024:11597-1"],"details":"A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qemu/qemu","events":[{"introduced":"25c4fde17775821182a76fb8ea2ba2223c5729b9"},{"fixed":"44f28df24767cf9dca1ddc9b23157737c4cbb645"},{"fixed":"bedd7e93d01961fcb16a97ae45d93acf357e11f6"}],"database_specific":{"cpe":"cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.10.0"},{"fixed":"6.2.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3748.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"14770436477810317024841570451115134811","length":2573},"id":"CVE-2021-3748-63a59022","signature_type":"Function","signature_version":"v1","source":"https://github.com/qemu/qemu/commit/bedd7e93d01961fcb16a97ae45d93acf357e11f6","target":{"file":"hw/net/virtio-net.c","function":"virtio_net_receive_rcu"}},{"deprecated":false,"digest":{"line_hashes":["139153011538441137443425885686769242333","19540242830036793152453911828632731321","261971490103105366185518487713065779809","274886746361350886814583306928039415769","117959129944310761007430404673458701437","5575847093833653024836064788740198304","164237186261067155017967658108932275749","41568830874794595423836708667899720764","204979634018619945530189025481137025000","200236562904088385766774625108108467906","81898909521356078802753323202918312736","276622600102277512342777352275962185101","17686686804455707955864788085310989909","170904657820958641358685323667703360232","20732383499291189554247390592397864623","104773052961933199236430616329051629652","30148309516638926374883201050847486195","263405443713322288624440308518443648446","43538856978998950359608723105896316473","135835704044671834425133687155795544491","53527990305242486942412336048341160685","298719444517055338988398675801988708732","162604734227819747815593254388199626104","202154863577782391529005710899301295034","102630445816527384348936569443744793486","107375714520255535024167627018508704968","337770536592677363347602484056375594828","329754777237505547929585834740495934718","309636159462361027173374396889853120124","172880516596470903830738622624501085703","112643539357749891484797476986660340522","259192748648542531221030014246801045362"],"threshold":0.9},"id":"CVE-2021-3748-b289847e","signature_type":"Line","signature_version":"v1","source":"https://github.com/qemu/qemu/commit/bedd7e93d01961fcb16a97ae45d93acf357e11f6","target":{"file":"hw/net/virtio-net.c"}}],"vanir_signatures_modified":"2026-07-09T01:07:07Z"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/qemu-project/qemu","events":[{"introduced":"25c4fde17775821182a76fb8ea2ba2223c5729b9"},{"fixed":"44f28df24767cf9dca1ddc9b23157737c4cbb645"}],"database_specific":{"cpe":"cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.10.0"},{"fixed":"6.2.0"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3748.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/04/msg00002.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202208-27"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220425-0004/"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1998514"},{"type":"FIX","url":"https://github.com/qemu/qemu/commit/bedd7e93d01961fcb16a97ae45d93acf357e11f6"},{"type":"FIX","url":"https://lists.nongnu.org/archive/html/qemu-devel/2021-09/msg00388.html"},{"type":"FIX","url":"https://ubuntu.com/security/CVE-2021-3748"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:21.10:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"18.04"},{"last_affected":"18.04"},{"introduced":"20.04"},{"last_affected":"20.04"},{"introduced":"21.10"},{"last_affected":"21.10"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"},{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"34"},{"last_affected":"34"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"},{"cpes":["cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux"},{"cpes":["cpe:2.3:o:redhat:enterprise_linux_advanced_virtualization_eus:8.4:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.4"},{"last_affected":"8.4"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux_advanced_virtualization_eus"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}