CVE-2020-25743

Severity
3.2LOW
EPSS
0.0%
top 86.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6
Latest updateMay 24

Description

hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:LExploitability: 1.5 | Impact: 1.4

Affected Packages2 packages

NVDqemu/qemu< 5.1.1

Also affects: Enterprise Linux 7.0, 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qgc2-rv3v-hg6j: hw/ide/pci2022-05-24
CVEList
CVE-2020-25743: hw/ide/pci2020-10-06
OSV
CVE-2020-25743: hw/ide/pci2020-10-06

📋Vendor Advisories

3
Microsoft
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.2020-10-13
Red Hat
QEMU: ide: null pointer dereference while cancelling i/o operation2020-06-24
Debian
CVE-2020-25743: qemu - hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because...2020

💬Community

5
Bugzilla
CVE-2020-25743 qemu: ide: null pointer dereference while cancelling i/o operation [fedora-all]2020-09-29
Bugzilla
CVE-2020-25743 xen: QEMU: ide: null pointer dereference while cancelling i/o operation [fedora-all]2020-09-29
Bugzilla
CVE-2020-25743 QEMU: ide: null pointer dereference while cancelling i/o operation2020-09-22
Bugzilla
CVE-2020-25743 qemu: ide: null pointer dereference while cancelling i/o operation [fedora-all]2020-09-22
Bugzilla
CVE-2020-25743 xen: QEMU: ide: null pointer dereference while cancelling i/o operation [fedora-all]2020-09-22
CVE-2020-25743 (LOW CVSS 3.2) | hw/ide/pci.c in QEMU before 5.1.1 c | cvebase.io