Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ch7h-w2mm-gm7m

Опубликовано: 27 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

EPSS

Процентиль: 32%
0.00124
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-400
CWE-667

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 3 лет назад

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

CVSS3: 3.2
redhat
больше 4 лет назад

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

CVSS3: 4.4
nvd
больше 3 лет назад

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

CVSS3: 4.4
debian
больше 3 лет назад

A deadlock issue was found in the AHCI controller device of QEMU. It o ...

EPSS

Процентиль: 32%
0.00124
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-400
CWE-667