A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.
Version | Score | Severity | Vector String |
---|---|---|---|
3.1 | 5.6 | Medium | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H |
Product | Vendor | Version |
---|---|---|
Extra Packages for Enterprise Linux | Fedora | 4.1.4 |
Fedora | Fedora | < publication |
Red Hat Enterprise Linux 6 | Red Hat | APQ8017 |
Red Hat Enterprise Linux 7 | Red Hat | <= * |
Red Hat Enterprise Linux 9 | Red Hat | <= None |
Red Hat Enterprise Linux 7 | Red Hat | AR8035 |
Red Hat OpenStack Platform 13 (Queens) | Red Hat | < publication |
Red Hat Enterprise Linux 8 Advanced Virtualization | Red Hat | <= 17.4 |
Red Hat Enterprise Linux 8 | Red Hat | CSRA6640 |
qemu | n/a | n/a |