CVE-2020-35505

Source
https://cve.org/CVERecord?id=CVE-2020-35505
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35505.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-35505
Downstream
Related
Published
2021-05-28T11:15:07.790Z
Modified
2026-07-08T05:56:06.631260924Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "10.0"
                },
                {
                    "last_affected": "10.0"
                }
            ],
            "source": "CPE_STRING",
            "vendor_product": "debian:debian_linux",
            "cpes": [
                "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
            ]
        }
    ]
}
References

Affected packages

Git / github.com/qemu/qemu

Affected ranges

Type
GIT
Repo
https://github.com/qemu/qemu
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.0.0"
        },
        {
            "introduced": "6.0.0-rc1"
        },
        {
            "last_affected": "6.0.0-rc1"
        },
        {
            "introduced": "6.0.0-rc2"
        },
        {
            "last_affected": "6.0.0-rc2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "cpe": [
        "cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:qemu:qemu:6.0.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:qemu:qemu:6.0.0:rc2:*:*:*:*:*:*"
    ]
}

Affected versions

6.*
6.0.0-rc1
6.0.0-rc2
v6.*
v6.0.0-rc1
v6.0.0-rc2
v6.0.0-rc3
v6.0.0-rc4
v6.0.0-rc5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35505.json"

Git / gitlab.com/qemu-project/qemu

Affected ranges

Type
GIT
Repo
https://gitlab.com/qemu-project/qemu
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.0.0"
        },
        {
            "introduced": "6.0.0-rc1"
        },
        {
            "last_affected": "6.0.0-rc1"
        },
        {
            "introduced": "6.0.0-rc2"
        },
        {
            "last_affected": "6.0.0-rc2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "cpe": [
        "cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:qemu:qemu:6.0.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:qemu:qemu:6.0.0:rc2:*:*:*:*:*:*"
    ]
}

Affected versions

6.*
6.0.0-rc1
6.0.0-rc2
v6.*
v6.0.0-rc1
v6.0.0-rc2
v6.0.0-rc3
v6.0.0-rc4
v6.0.0-rc5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35505.json"