cbcvebase.
CVE-2020-35505
published 2021-05-28

CVE-2020-35505: A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling…

PriorityP414medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.32%
23.8th percentile
A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianqemu< qemu 1:6.0+dfsg-3 (bookworm)qemu 1:6.0+dfsg-3 (bookworm)
msrccm1_qemu-kvm_4.2.0-46_on_cbl_mariner_1.0
qemuqemu< 6.0.06.0.0
qemuqemu
qemuqemu
qemuqemu>= 0 < 1:6.0+dfsg-31:6.0+dfsg-3
qemuqemu>= 0 < 1:6.0+dfsg-31:6.0+dfsg-3
qemuqemu>= 0 < 1:6.0+dfsg-31:6.0+dfsg-3
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.371:2.11+dfsg-1ubuntu7.37
qemuqemu>= 0 < 1:4.2-3ubuntu6.171:4.2-3ubuntu6.17
ubuntuqemu

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_msrc4.4MEDIUM
vendor_redhat4.4MEDIUM
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.