Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cp42-9j6q-v649

Опубликовано: 13 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.6

Описание

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

EPSS

Процентиль: 0%
0.00006
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 5.6
ubuntu
почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
redhat
около 2 лет назад

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
nvd
почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 5.6
debian
почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a rac ...

EPSS

Процентиль: 0%
0.00006
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-362