Lucene search

K
osvGoogleOSV:CVE-2020-35504
HistoryMay 28, 2021 - 11:15 a.m.

CVE-2020-35504

2021-05-2811:15:07
Google
osv.dev
8
qemu
scsi emulation
vulnerability
system availability
denial of service

AI Score

6.1

Confidence

High

EPSS

0

Percentile

14.2%

A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.