Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18262
HistoryMay 02, 2019 - 6:36 a.m.

Null Pointer Dereference

2019-05-0206:36:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.001 Low

EPSS

Percentile

26.7%

QEMU is vulnerable to null pointer dereference attacks. This occurs in the virtqueue_map_desc function in hw/virtio/virtio.c. Local guest OS administrators could cause a denial of service via a large I/O descriptor buffer length value which leads QEMU process to crash.

References