LOW 3.8 Microsoft
CVE-2020-16092
In QEMU through 5.0.0 an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.
Microsoft Security Update 2020-Aug: In QEMU through 5.0.0 an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.
Affected Products
- cm1 qemu-kvm 4.2.0-13 on CBL Mariner 1.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-16092
- https://nvd.nist.gov/vuln/detail/CVE-2020-16092
This low severity vulnerability with a CVSS score of 3.8 was published on 2020-08-11 via Microsoft. Affected: cm1 qemu-kvm 4.2.0-13 on CBL Mariner 1.0.
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.