PT-2020-6468 · Qemu+4 · Qemu+4
Eric Blake
+1
·
Published
2020-06-09
·
Updated
2024-06-15
·
CVE-2020-10761
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
QEMU versions prior to 5.0.1
Description
An assertion failure issue was found in the Network Block Device (NBD) Server. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server, resulting in a denial of service.
Recommendations
For QEMU versions prior to 5.0.1, update to QEMU 5.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the NBD server to minimize the risk of exploitation.
Fix
DoS
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Qemu
Suse
Ubuntu