CVE-2021-3713
NixOS vulnerability analysis and mitigation

Overview

An out-of-bounds write vulnerability was discovered in the UAS (USB Attached SCSI) device emulation of QEMU, identified as CVE-2021-3713. The vulnerability was introduced in QEMU v1.5.0 and fixed in version 6.2.0-rc0. The issue occurs due to missing sanity checks in the usbuashandledata() function in hw/usb/dev-uas.c, where the device uses the guest-supplied stream number unchecked ([Bugzilla Report](https://bugzilla.redhat.com/showbug.cgi?id=1994640)).

Technical details

The vulnerability exists in the UAS device emulation where the device uses the guest-supplied stream number without proper validation. This leads to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. The issue was introduced through a commit in QEMU v1.5.0 (Bugzilla Report).

Impact

A malicious guest user could potentially exploit this vulnerability to crash QEMU or achieve code execution with the privileges of the QEMU process on the host. However, it's worth noting that the UAS device emulation is not in widespread use, as the classic USB storage device using the BOT (Bulk Only transport) protocol is much more popular and is the only device supported by libvirt (Bugzilla Report).

Mitigation and workarounds

The vulnerability has been fixed in QEMU version 6.2.0-rc0. Users are advised to upgrade to this version or later. Various distributions have also released patches for their respective versions: Ubuntu has released updates for version 21.10 (Ubuntu Security), Debian has provided fixes in version 1:2.8+dfsg-6+deb9u15 (Debian LTS), and Red Hat has addressed the issue in their repositories.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-65799MEDIUM4.3
  • NixOSNixOS
  • memos
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management