VYPR
Low severity3.2NVD Advisory· Published Mar 23, 2021· Updated Jun 17, 2026

CVE-2021-3392

CVE-2021-3392

Description

A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • QEMU/Qemu3 versions
    cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*range: >=2.10.0,<=5.2.0
    • (no CPE)range: >=2.10.0 <=5.2.0
    • (no CPE)range: between 2.10.0 and 5.2.0
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.