Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25742

Опубликовано: 24 июн. 2020
Источник: redhat
CVSS3: 3.2
EPSS Низкий

Описание

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

A NULL pointer dereference flaw was found in the LSI53C895A SCSI Host Bus Adapter emulator of QEMU. This flaw occurs while processing 'Memory Move' instructions to move data between DMA memory and I/O address space via lsi_memcpy(). This flaw allows a guest user or process to crash the QEMU process, resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 5xenNot affected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 7qemu-kvm-rhevNot affected
Red Hat Enterprise Linux 8qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationqemu-kvmNot affected
Red Hat Enterprise Linux 9qemu-kvmNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1883178QEMU: scsi: lsi: null pointer dereference during memory move

EPSS

Процентиль: 13%
0.00044
Низкий

3.2 Low

CVSS3

Связанные уязвимости

CVSS3: 3.2
ubuntu
больше 4 лет назад

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

CVSS3: 3.2
nvd
больше 4 лет назад

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

CVSS3: 3.2
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 3.2
debian
больше 4 лет назад

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL p ...

github
около 3 лет назад

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

EPSS

Процентиль: 13%
0.00044
Низкий

3.2 Low

CVSS3