Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9gg5-9c3q-7g76

Опубликовано: 18 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.2

Описание

An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

EPSS

Процентиль: 5%
0.00022
Низкий

3.2 Low

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 3.2
ubuntu
около 3 лет назад

An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

CVSS3: 3.2
redhat
почти 5 лет назад

An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

CVSS3: 3.2
nvd
около 3 лет назад

An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

CVSS3: 3.2
debian
около 3 лет назад

An infinite loop flaw was found in the USB xHCI controller emulation o ...

CVSS3: 3.2
fstec
около 3 лет назад

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с циклом с недостижимым условием выхода, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 5%
0.00022
Низкий

3.2 Low

CVSS3

Дефекты

CWE-835