CVE-2020-25743 PUBLISHED

hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

EPSS 0.04% · 13.3th percentile

Risk Scores

EPSS Score
0.04%
13.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSqemu1:2.11+dfsg-1ubuntu7.38, 1:2.11+dfsg-1ubuntu7.39, 1:2.11+dfsg-1ubuntu7.40
Ubuntu:Pro:16.04:LTSqemu1:2.5+dfsg-5ubuntu10.13, 1:2.5+dfsg-5ubuntu10.14, 1:2.5+dfsg-5ubuntu10.16
Ubuntu:Pro:14.04:LTSqemu*, 1.5.0+dfsg-3ubuntu6, 1.6.0+dfsg-2ubuntu1
Ubuntu:24.04:LTSqemu1:8.0.4+dfsg-1ubuntu3, 1:8.2.2+ds-0ubuntu1.2, 1:8.2.2+ds-0ubuntu1
Ubuntu:25.10qemu*, *, 1:10.1.0+ds-5ubuntu2.2
Ubuntu:22.04:LTSqemu1:6.2+dfsg-2ubuntu6.22, 0, 1:6.0+dfsg-2expubuntu1
Ubuntu:20.04:LTSqemu1:4.2-3ubuntu6.2, 0, 1:4.2-3ubuntu5

Timeline

References

Open in Interactive Console →