PublicCVE

CVE-2020-10761

MEDIUM5.0JSON exportCreate alert

Description

An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
Low

Affected products

  • Red Hat / QEMUall QEMU versions before QEMU 5.0.1 – all QEMU versions before QEMU 5.0.1