Wind River Support Network

HomeDefectsLIN9-10216
Fixed

LIN9-10216 : Security Advisory - qemu - CVE-2020-16092

Created: Aug 11, 2020    Updated: Apr 21, 2022
Resolved Date: Aug 20, 2020
Found In Version: 9.0.0.1
Fix Version: 9.0.0.26
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.

CREATE(Triage):(User=admin) CVE-2020-16092 (https://nvd.nist.gov/vuln/detail/CVE-2020-16092)

CVEs


Live chat
Online