{"id":"CVE-2021-3735","details":"A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.","modified":"2026-07-08T05:57:13.874092788Z","published":"2022-08-26T16:15:09.467Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"10.0"},{"last_affected":"10.0"},{"introduced":"11.0"},{"last_affected":"11.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"}]},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2021-3735"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-3735"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250228-0009/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1997184"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qemu/qemu","events":[{"introduced":"ecf2706e271fa705621f0d5ad9517fe15a22bf22"},{"last_affected":"ecf2706e271fa705621f0d5ad9517fe15a22bf22"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:qemu:qemu:6.1.0:rc4:*:*:*:*:*:*","extracted_events":[{"introduced":"6.1.0-rc4"},{"last_affected":"6.1.0-rc4"}]}}],"versions":["6.1.0-rc4","v6.1.0-rc4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3735.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/qemu-project/qemu","events":[{"introduced":"ecf2706e271fa705621f0d5ad9517fe15a22bf22"},{"last_affected":"ecf2706e271fa705621f0d5ad9517fe15a22bf22"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:qemu:qemu:6.1.0:rc4:*:*:*:*:*:*","extracted_events":[{"introduced":"6.1.0-rc4"},{"last_affected":"6.1.0-rc4"}]}}],"versions":["6.1.0-rc4","v6.1.0-rc4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3735.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"}]}