Vulnerability Description
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qemu | Qemu | < 7.0.0 |
| Fedoraproject | Fedora | 35 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2021-3929Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2020298Issue TrackingPatchThird Party Advisory
- https://gitlab.com/qemu-project/qemu/-/commit/736b01642d85be832385PatchThird Party Advisory
- https://gitlab.com/qemu-project/qemu/-/issues/556Issue TrackingThird Party Advisory
- https://gitlab.com/qemu-project/qemu/-/issues/782ExploitIssue TrackingPatch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://access.redhat.com/security/cve/CVE-2021-3929Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2020298Issue TrackingPatchThird Party Advisory
- https://gitlab.com/qemu-project/qemu/-/commit/736b01642d85be832385PatchThird Party Advisory
- https://gitlab.com/qemu-project/qemu/-/issues/556Issue TrackingThird Party Advisory
- https://gitlab.com/qemu-project/qemu/-/issues/782ExploitIssue TrackingPatch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20250228-0010/
FAQ
What is CVE-2021-3929?
CVE-2021-3929 is a vulnerability with a CVSS score of 8.2 (HIGH). A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function n...
How severe is CVE-2021-3929?
CVE-2021-3929 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3929?
Check the references section above for vendor advisories and patch information. Affected products include: Qemu Qemu, Fedoraproject Fedora.