SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-10761

A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.

MEDIUM 5.0EPSS 1.80%

Does this matter?

Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.

Description

An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.

CVSS 3.1
5.0 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
EPSS
1.80% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-617
Affected
qemu/qemu · redhat/enterprise linux · opensuse/leap · canonical/ubuntu linux
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.