Lucene search

K
cve[email protected]CVE-2020-25743
HistoryOct 06, 2020 - 3:15 p.m.

CVE-2020-25743

2020-10-0615:15:15
CWE-476
web.nvd.nist.gov
90
cve
2020
25743
qemu
null pointer
dereference

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.2 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L

4.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%

hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

Affected configurations

NVD
Node
qemuqemuRange<5.1.1
Node
redhatopenstack_platformMatch13.0
OR
redhatenterprise_linuxMatch7.0
OR
redhatenterprise_linuxMatch8.0-
OR
redhatenterprise_linuxMatch8.0advanced_virtualization
CPENameOperatorVersion
qemu:qemuqemult5.1.1

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.2 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L

4.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%