CVE-2020-25741NULL Pointer Dereference in Qemu

Severity
3.2LOWNVD
EPSS
0.2%
top 63.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 2
Latest updateMay 24

Description

fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the current drive.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:LExploitability: 1.5 | Impact: 1.4

Affected Packages2 packages

NVDqemu/qemu5.0.0
debiandebian/qemu

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gj53-3vwp-f632: fdctrl_write_data in hw/block/fdc2022-05-24
OSV
CVE-2020-25741: fdctrl_write_data in hw/block/fdc2020-10-02

📋Vendor Advisories

2
Red Hat
QEMU: fdc: null pointer dereference during r/w data transfer2020-06-24
Debian
CVE-2020-25741: qemu - fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference...2020

💬Community

3
Bugzilla
CVE-2020-25741 xen: QEMU: fdc: null pointer dereference during r/w data transfer [fedora-all]2020-09-22
Bugzilla
CVE-2020-25741 qemu: fdc: null pointer dereference during r/w data transfer [fedora-all]2020-09-22
Bugzilla
CVE-2020-25741 QEMU: fdc: null pointer dereference during r/w data transfer2020-09-22