PT-2020-6719 · Qemu+6 · Qemu+6

Published

2020-12-17

·

Updated

2022-09-22

·

CVE-2020-35505

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 6.0.0
Description A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU. This issue occurs while handling the 'Information Transfer' command. The flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Recommendations For versions prior to 6.0.0, update to version 6.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the am53c974 SCSI host bus adapter emulation to minimize the risk of exploitation.

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1767
BDU:2022-05768
CVE-2020-35505
DLA-3099-1
OESA-2021-1241
OPENSUSE-SU-2021:1202-1
OPENSUSE-SU-2021:2789-1
OPENSUSE-SU-2021:2858-1
OPENSUSE-SU-2021:3614-1
OPENSUSE-SU-2021_1202-1
OPENSUSE-SU-2021_2789-1
OPENSUSE-SU-2021_2858-1
OPENSUSE-SU-2021_3614-1
SUSE-SU-2021:2789-1
SUSE-SU-2021:2813-1
SUSE-SU-2021:2858-1
SUSE-SU-2021:3575-1
SUSE-SU-2021:3613-1
SUSE-SU-2021:3614-1
SUSE-SU-2021:3635-1
USN-5010-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Qemu
Suse
Ubuntu