4.4 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:M/Au:N/C:P/I:P/A:P
5 Medium
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
6.8 Medium
AI Score
Confidence
High
0.0005 Low
EPSS
Percentile
17.2%
Ziming Zhang, Xiao Wei, Gonglei Arei, and Yanyu Zhang discovered that QEMU
incorrectly handled certain USB packets. An attacker inside the guest could
use this issue to cause QEMU to crash, resulting in a denial of service, or
possibly execute arbitrary code on the host. In the default installation,
when QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 20.04 | noarch | qemu | < 1:4.2-3ubuntu6.6 | UNKNOWN |
Ubuntu | 20.04 | noarch | qemu-block-extra | < 1:4.2-3ubuntu6.6 | UNKNOWN |
Ubuntu | 20.04 | noarch | qemu-block-extra-dbgsym | < 1:4.2-3ubuntu6.6 | UNKNOWN |
Ubuntu | 20.04 | noarch | qemu-guest-agent | < 1:4.2-3ubuntu6.6 | UNKNOWN |
Ubuntu | 20.04 | noarch | qemu-guest-agent-dbgsym | < 1:4.2-3ubuntu6.6 | UNKNOWN |
Ubuntu | 20.04 | noarch | qemu-kvm | < 1:4.2-3ubuntu6.6 | UNKNOWN |
Ubuntu | 20.04 | noarch | qemu-system | < 1:4.2-3ubuntu6.6 | UNKNOWN |
Ubuntu | 20.04 | noarch | qemu-system-arm | < 1:4.2-3ubuntu6.6 | UNKNOWN |
Ubuntu | 20.04 | noarch | qemu-system-arm-dbgsym | < 1:4.2-3ubuntu6.6 | UNKNOWN |
Ubuntu | 20.04 | noarch | qemu-system-common | < 1:4.2-3ubuntu6.6 | UNKNOWN |
4.4 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:M/Au:N/C:P/I:P/A:P
5 Medium
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
6.8 Medium
AI Score
Confidence
High
0.0005 Low
EPSS
Percentile
17.2%