VulnerabilityModified
CVE-2020-10761
A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
MEDIUM 5.0EPSS 1.80%
Does this matter?
Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.
Description
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
- CVSS 3.1
- 5.0 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Affected
- qemu/qemu · redhat/enterprise linux · opensuse/leap · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.htmlMailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10761Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/202011-09Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200731-0001/Third Party Advisory
- https://usn.ubuntu.com/4467-1/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2020/06/09/1Mailing List, Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.htmlMailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10761Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/202011-09Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200731-0001/Third Party Advisory
- https://usn.ubuntu.com/4467-1/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2020/06/09/1Mailing List, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.