Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:42143
HistoryAug 05, 2023 - 3:34 a.m.

Denial Of Service (DoS)

2023-08-0503:34:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
qemu
vulnerable
net device backend
attack
denial of service

CVSS3

5.6

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

EPSS

0

Percentile

5.1%

qemu is vulnerable to Denial of Service (DoS) attacks. Because hot-unplug is async, a race condition can occur in which the net device backend is cleared before the virtio-net pci frontend is removed. This time window might be used by a malicious attacker to trigger an assertion and cause a denial of service.

CVSS3

5.6

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

EPSS

0

Percentile

5.1%