VulnerabilityModified
CVE-2020-16092
A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.
LOW 3.8EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.
- CVSS 3.1
- 3.8 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Affected
- qemu/qemu · debian/debian linux · canonical/ubuntu linux · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00024.htmlMailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/08/10/1Mailing List, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00013.htmlMailing List, Third Party Advisory
- https://lists.nongnu.org/archive/html/qemu-devel/2020-07/msg07563.htmlMailing List, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202208-27Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200821-0006/Third Party Advisory
- https://usn.ubuntu.com/4467-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4760Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00024.htmlMailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/08/10/1Mailing List, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00013.htmlMailing List, Third Party Advisory
- https://lists.nongnu.org/archive/html/qemu-devel/2020-07/msg07563.htmlMailing List, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202208-27Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200821-0006/Third Party Advisory
- https://usn.ubuntu.com/4467-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4760Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.