VYPR
Medium severity5.5NVD Advisory· Published Feb 18, 2022· Updated Jun 17, 2026

CVE-2021-3947

CVE-2021-3947

Description

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • QEMU/Qemu4 versions
    cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.1.0
    • cpe:2.3:a:qemu:qemu:6.2.0:rc0:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:6.2.0:rc1:*:*:*:*:*:*
    • (no CPE)range: qemu-kvm 6.2.0-rc2
  • QEMU/NVMEllm-create

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.