CVE Vulnerabilities

CVE-2021-20257

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Mar 16, 2022 | Modified: Feb 12, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.2 LOW
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
Ubuntu
MEDIUM

An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu * 6.2.0 (excluding)
Qemu Ubuntu bionic *
Qemu Ubuntu esm-infra-legacy/trusty *
Qemu Ubuntu esm-infra/xenial *
Qemu Ubuntu focal *
Qemu Ubuntu groovy *
Qemu Ubuntu trusty *
Qemu Ubuntu trusty/esm *
Qemu Ubuntu xenial *
Qemu-kvm Ubuntu precise/esm *
Advanced Virtualization for RHEL 8.5.0.Z RedHat virt:av-8050020211203164130.c5368500 *
Advanced Virtualization for RHEL 8.5.0.Z RedHat virt-devel:av-8050020211203164130.c5368500 *
Red Hat Enterprise Linux 8 RedHat virt-devel:rhel-8050020211203195115.c5368500 *
Red Hat Enterprise Linux 8 RedHat virt:rhel-8050020211203195115.c5368500 *

References