[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2020-14394Date: (C)2022-08-19   (M)2024-05-30


An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 3.2CVSS Score :
Exploit Score: 1.5Exploit Score:
Impact Score: 1.4Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector:
Attack Complexity: LOWAccess Complexity:
Privileges Required: HIGHAuthentication:
User Interaction: NONEConfidentiality:
Scope: CHANGEDIntegrity:
Confidentiality: NONEAvailability:
Integrity: NONE 
Availability: LOW 
  
Reference:
FEDORA-2022-22b1f8dae2
https://lists.debian.org/debian-lts-announce/2023/03/msg00013.html
https://bugzilla.redhat.com/show_bug.cgi?id=1908004
https://gitlab.com/qemu-project/qemu/-/issues/646

CPE    2
cpe:/o:redhat:enterprise_linux:5.0
cpe:/o:redhat:enterprise_linux:7.0
CWE    1
CWE-835
OVAL    8
oval:org.secpod.oval:def:124744
oval:org.secpod.oval:def:89048604
oval:org.secpod.oval:def:89048567
oval:org.secpod.oval:def:89048487
...

© SecPod Technologies