cbcvebase.
CVE-2020-25723
published 2020-12-02

CVE-2020-25723: A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA…

PriorityP49low3.2CVSS 3.1
AVLACLPRHUINSCCNINAL
EPSS
0.36%
27.8th percentile
A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host, resulting in a denial of service.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianqemu< qemu 1:5.2+dfsg-1 (bookworm)qemu 1:5.2+dfsg-1 (bookworm)
msrccm1_qemu-kvm_4.2.0-22_on_cbl_mariner_1.0
qemuqemu<= 5.1.1
qemuqemu
qemuqemu>= 0 < 1:5.2+dfsg-11:5.2+dfsg-1
qemuqemu>= 0 < 1:5.2+dfsg-11:5.2+dfsg-1
qemuqemu>= 0 < 1:5.2+dfsg-11:5.2+dfsg-1
qemuqemu>= 0 < 1:5.2+dfsg-11:5.2+dfsg-1
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.481:2.5+dfsg-5ubuntu10.48
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.341:2.11+dfsg-1ubuntu7.34
qemuqemu>= 0 < 1:4.2-3ubuntu6.101:4.2-3ubuntu6.10
ubuntuqemu

CVSS provenance

nvdv3.13.2LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.3MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian3.2LOW
vendor_msrc3.2LOW
vendor_redhat3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.