CVE Database
/

CVE-2020-10761

Back to search

CVE-2020-10761

Published: Jun 9, 2020

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.1

5.0

MEDIUM

Description

An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.

VendorProductVersions

Red Hat

QEMU:

affected
all QEMU versions before QEMU 5.0.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

None

Availability

Low

References

openSUSE-SU-2020:1108
vendor-advisory
x_refsource_SUSE
USN-4467-1
vendor-advisory
x_refsource_UBUNTU
GLSA-202011-09
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now