Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20196

Опубликовано: 23 янв. 2021
Источник: redhat
CVSS3: 3.2
EPSS Низкий

Описание

A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Отчет

This issue affects the version of the qemu-kvm package shipped with Red Hat Enterprise Linux 5, 6, 7 and 8. Future qemu-kvm package updates for Red Hat Enterprise Linux 7 and 8 may address this issue. This has been rated as having Low security impact and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 5 & 6. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmOut of support scope
Red Hat Enterprise Linux 5xenOut of support scope
Red Hat Enterprise Linux 6qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvmFix deferred
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 7qemu-kvm-rhevFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/qemu-kvmFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmAffected
Red Hat OpenStack Platform 10 (Newton)qemu-kvm-rhevWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1919210QEMU: block: fdc: null pointer dereference may lead to guest crash

EPSS

Процентиль: 7%
0.00031
Низкий

3.2 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
nvd
около 4 лет назад

A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
debian
около 4 лет назад

A NULL pointer dereference flaw was found in the floppy disk emulator ...

suse-cvrf
больше 3 лет назад

Security update for qemu

suse-cvrf
больше 3 лет назад

Security update for qemu

EPSS

Процентиль: 7%
0.00031
Низкий

3.2 Low

CVSS3