PT-2020-6468 · Qemu+4 · Qemu+4

Eric Blake

+1

·

Published

2020-06-09

·

Updated

2024-06-15

·

CVE-2020-10761

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 5.0.1
Description An assertion failure issue was found in the Network Block Device (NBD) Server. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server, resulting in a denial of service.
Recommendations For QEMU versions prior to 5.0.1, update to QEMU 5.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the NBD server to minimize the risk of exploitation.

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2431
ALT-PU-2020-2595
ALT-PU-2021-1880
ALT-PU-2021-1964
BDU:2021-05172
CVE-2020-10761
OPENSUSE-SU-2020:1108-1
OPENSUSE-SU-2020_1108-1
OPENSUSE-SU-2024:11287-1
SUSE-SU-2020:2015-1
SUSE-SU-2020_2015-1
USN-4467-1
USN-4467-3

Affected Products

Alt Linux
Linuxmint
Qemu
Suse
Ubuntu