CVE-2020-14394

Published Aug 17, 2022

Last updated a year ago

Overview

Description
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
Source
secalert@redhat.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
3.2
Impact score
1.4
Exploitability score
1.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
Severity
LOW

Weaknesses

nvd@nist.gov
CWE-835
secalert@redhat.com
CWE-835

Social media

Hype score
Not currently trending

Configurations