CVE-2020-25743
Severity
3.2LOW
EPSS
0.0%
top 86.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 6
Latest updateMay 24
Description
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:LExploitability: 1.5 | Impact: 1.4
Affected Packages2 packages
Also affects: Enterprise Linux 7.0, 8.0
Patches
🔴Vulnerability Details
3📋Vendor Advisories
3💬Community
5Bugzilla▶
CVE-2020-25743 qemu: ide: null pointer dereference while cancelling i/o operation [fedora-all]↗2020-09-29
Bugzilla▶
CVE-2020-25743 xen: QEMU: ide: null pointer dereference while cancelling i/o operation [fedora-all]↗2020-09-29
Bugzilla
▶
Bugzilla▶
CVE-2020-25743 qemu: ide: null pointer dereference while cancelling i/o operation [fedora-all]↗2020-09-22
Bugzilla▶
CVE-2020-25743 xen: QEMU: ide: null pointer dereference while cancelling i/o operation [fedora-all]↗2020-09-22