CVE-2020-35504
Published: August 31, 2023Last modified: August 31, 2023
Description
A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 6 | 
| Attack Vector | LOCAL | 
| Attack complexity | LOW | 
| Privileges required | HIGH | 
| User interaction | NONE | 
| Scope | CHANGED | 
| Confidentiality | NONE | 
| Integrity impact | NONE | 
| Availability impact | HIGH | 
| Vector | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H | 
Status
| Product | Release | Package | Status | 
|---|---|---|---|
| Alpaquita Linux | 23 LTS | qemu | Not affected (7.1.0-r4) | 
| Stream | qemu | Not affected (8.0.4-r0) | 
References
- http://www.openwall.com/lists/oss-security/2021/04/16/3
 - https://bugzilla.redhat.com/show_bug.cgi?id=1909766
 - https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html
 - https://security.gentoo.org/glsa/202208-27
 - https://security.netapp.com/advisory/ntap-20210713-0006/
 - https://www.openwall.com/lists/oss-security/2021/04/16/3