CVE-2020-25743
published 2020-10-06CVE-2020-25743: hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
PriorityP48low3.2CVSS 3.1
AVLACLPRHUINSCCNINAL
EPSS
0.47%
37.5th percentile
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | — | — |
| msrc | cm1_qemu-kvm_4.2.0-21_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | < 5.1.1 | 5.1.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.13.2LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv3.2LOW
vendor_debian3.2LOW
vendor_msrc3.2LOW
vendor_redhat3.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
vendor_msrc·2020-10-13·CVSS 3.2
CVE-2020-25743 [LOW] CWE-476 hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Cust
Red Hat
QEMU: ide: null pointer dereference while cancelling i/o operation
vendor_redhat·2020-06-24·CVSS 3.2
CVE-2020-25743 [LOW] CWE-476 QEMU: ide: null pointer dereference while cancelling i/o operation
QEMU: ide: null pointer dereference while cancelling i/o operation
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
A NULL pointer dereference flaw was found in the IDE disk emulator of QEMU. This issue occurs while canceling an I/O operation via the ide_cancel_dma_sync() routine if a block drive pointer is null. This flaw allows a guest user to crash the QEMU process on the host, resulting in a denial of service.
Statement: In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP qemu-kvm-rhev package.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package:
Debian
CVE-2020-25743: qemu - hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because...
vendor_debian·2020·CVSS 3.2
CVE-2020-25743 [LOW] CVE-2020-25743: qemu - hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because...
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-qgc2-rv3v-hg6j: hw/ide/pci
ghsa_unreviewed·2022-05-24
CVE-2020-25743 [LOW] GHSA-qgc2-rv3v-hg6j: hw/ide/pci
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
OSV
CVE-2020-25743: hw/ide/pci
osv·2020-10-06·CVSS 3.2
CVE-2020-25743 [LOW] CVE-2020-25743: hw/ide/pci
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25743 qemu: ide: null pointer dereference while cancelling i/o operation [fedora-all]
bugzilla·2020-09-29·CVSS 3.2
CVE-2020-25743 [LOW] CVE-2020-25743 qemu: ide: null pointer dereference while cancelling i/o operation [fedora-all]
CVE-2020-25743 qemu: ide: null pointer dereference while cancelling i/o operation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2020-25743 xen: QEMU: ide: null pointer dereference while cancelling i/o operation [fedora-all]
bugzilla·2020-09-29·CVSS 3.2
CVE-2020-25743 [LOW] CVE-2020-25743 xen: QEMU: ide: null pointer dereference while cancelling i/o operation [fedora-all]
CVE-2020-25743 xen: QEMU: ide: null pointer dereference while cancelling i/o operation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2020-25743 QEMU: ide: null pointer dereference while cancelling i/o operation
bugzilla·2020-09-22·CVSS 3.2
CVE-2020-25743 [LOW] CVE-2020-25743 QEMU: ide: null pointer dereference while cancelling i/o operation
CVE-2020-25743 QEMU: ide: null pointer dereference while cancelling i/o operation
A null pointer dereference issue was found in the IDE disk emulator of QEMU. It could occur while cancelling an i/o operation via ide_cancel_dma_sync() routine, if a block drive pointer is null. A guest may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
Upstream patch:
-> https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg01568.html
Discussion:
Acknowledgments:
Name: Sergej Schumilo (Ruhr-University Bochum), Cornelius Aschermann (Ruhr-University Bochum), Simon Wrner (Ruhr-University Bochum)
---
External References:
https://www.openwall.com/lists/oss-security/2020/09/29/1
https://ruhr-uni-bochum.sciebo.de/s/NNWP2GfwzYKeKwE?path=%2Fide_nullptr1b
---
Created qem
Bugzilla
CVE-2020-25743 qemu: ide: null pointer dereference while cancelling i/o operation [fedora-all]
bugzilla·2020-09-22·CVSS 3.2
CVE-2020-25743 [LOW] CVE-2020-25743 qemu: ide: null pointer dereference while cancelling i/o operation [fedora-all]
CVE-2020-25743 qemu: ide: null pointer dereference while cancelling i/o operation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2020-25743 xen: QEMU: ide: null pointer dereference while cancelling i/o operation [fedora-all]
bugzilla·2020-09-22·CVSS 3.2
CVE-2020-25743 [LOW] CVE-2020-25743 xen: QEMU: ide: null pointer dereference while cancelling i/o operation [fedora-all]
CVE-2020-25743 xen: QEMU: ide: null pointer dereference while cancelling i/o operation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
http://www.openwall.com/lists/oss-security/2020/09/29/1https://bugzilla.redhat.com/show_bug.cgi?id=1881409https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg05967.htmlhttps://ruhr-uni-bochum.sciebo.de/s/NNWP2GfwzYKeKwE?path=%2Fide_nullptr1bhttp://www.openwall.com/lists/oss-security/2020/09/29/1https://bugzilla.redhat.com/show_bug.cgi?id=1881409https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg05967.htmlhttps://ruhr-uni-bochum.sciebo.de/s/NNWP2GfwzYKeKwE?path=%2Fide_nullptr1b
2020-10-06
Published