4.4

CVE-2020-35505

A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qemu ≫ Qemu Version < 6.0.0
Qemu ≫ Qemu Version 6.0.0 Update rc1
Qemu ≫ Qemu Version 6.0.0 Update rc2
Debian ≫ Debian Linux Version 10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.242
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/202208-27
Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/16/3
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20210713-0006/
Third Party Advisory
https://www.openwall.com/lists/oss-security/2021/04/16/3
Patch
Third Party Advisory
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=1909769
Patch
Third Party Advisory
Issue Tracking