PT-2020-12296 · Qemu+1 · Qemu+1

Yuval Avrahami

·

Published

2020-05-04

·

Updated

2024-06-15

·

CVE-2020-10717

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions >= v5.0
Description A potential denial of service flaw was found in the virtio-fs shared file system daemon implementation. This issue occurs when a guest opens the maximum number of file descriptors under the shared directory, allowing a guest user or process to cause a denial of service on the host. Virtio-fs is designed to share a host file system directory with a guest via a virtio-fs device.
Recommendations For QEMU versions >= v5.0, consider restricting the number of file descriptors that can be opened by a guest under the shared directory to prevent a denial of service. As a temporary workaround, limiting the access to the shared directory or implementing resource limits for guest users/processes may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2595
CVE-2020-10717
OPENSUSE-SU-2024:11287-1

Affected Products

Alt Linux
Qemu