In QEMU through 5.0.0, an assertion failure can occur in...
Vulnerability Description
In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-16092
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lists.nongnu.org/archive/html/qemu-devel/2020-07/msg07563.html
- http://www.openwall.com/lists/oss-security/2020/08/10/1
- https://security.netapp.com/advisory/ntap-20200821-0006/
- https://usn.ubuntu.com/4467-1/
- https://www.debian.org/security/2020/dsa-4760
- https://lists.debian.org/debian-lts-announce/2020/09/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00024.html
- https://security.gentoo.org/glsa/202208-27
More from qemu
View All →Affected Vendor
qemu
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.