« List of all CVEs

CVE-2020-10761

Published: 6/9/2020 Last updated: 8/4/2024 Reserved: 3/20/2020

An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5 Medium CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L

Opam packages affected (2)

conf-qemu-img nbd-tool

Products affected (1)

Product Vendor Version
QEMU: Red Hat < abe3cfb7a7c8e907b312c7dbd7bf4d142b745aa8

References (12)