GPU VulnDB

Database/Kernel, userspace & hypervisor

QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU process

CVE-2021-3748Kernel, userspace & hypervisorcurated

Impact

Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU process

Who can reach it

Tenant VM guest

What to do

QEMU package update + restart each VM's qemu process. Live-migrate to patched hosts to avoid tenant downtime; GPU-passthrough VMs cannot live-migrate, so this becomes a scheduled drain

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.