cbcvebase.
CVE-2020-14394
published 2022-08-17

CVE-2020-14394: An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw…

low3.2CVSS 3.1
AVLACLPRHUINSCCNINAL
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:7.1+dfsg-1 (bookworm)qemu 1:7.1+dfsg-1 (bookworm)
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
fedoraprojectfedora
qemuqemu
qemuqemu
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u3
qemuqemu>= 0 < 1:7.1+dfsg-11:7.1+dfsg-1
qemuqemu>= 0 < 1:7.1+dfsg-11:7.1+dfsg-1
qemuqemu>= 0 < 1:7.1+dfsg-11:7.1+dfsg-1
qemuqemu>= 0 < 1:4.2-3ubuntu6.281:4.2-3ubuntu6.28
qemuqemu>= 0 < 1:4.2-3ubuntu6.291:4.2-3ubuntu6.29
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.161:6.2+dfsg-2ubuntu6.16
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.211:6.2+dfsg-2ubuntu6.21
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatopenstack_platform
redhatopenstack_platform

CVSS provenance

nvdv3.13.2LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
osv3.2LOW