An assertion failure issue was found in the Network Block...
Vulnerability Description
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-10761
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.openwall.com/lists/oss-security/2020/06/09/1
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10761
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.html
- https://security.netapp.com/advisory/ntap-20200731-0001/
- https://usn.ubuntu.com/4467-1/
- https://security.gentoo.org/glsa/202011-09
More from Red Hat
View All →Affected Vendor
Red Hat
View all reports →