VDB

CVE-2020-35503

CVE-2020-35503 PUBLISHED

A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dropping a SCSI request. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

EPSS 0.02% · 7.1th percentile

Risk Scores

EPSS Score
0.02%
7.1th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSqemu0, 1:6.0+dfsg-2expubuntu1, 1:6.0+dfsg-2expubuntu2
Ubuntu:Pro:14.04:LTSqemu2.0.0+dfsg-2ubuntu1.26, 2.0.0+dfsg-2ubuntu1.24, 2.0.0+dfsg-2ubuntu1.22
Ubuntu:25.10qemu1:10.0.2+ds-1ubuntu2, 1:10.1.0+ds-1ubuntu1, 1:10.1.0+ds-5ubuntu2
Ubuntu:Pro:18.04:LTSqemu1:2.11+dfsg-1ubuntu7.15, 1:2.11+dfsg-1ubuntu7.17, 1:2.11+dfsg-1ubuntu7.18
Ubuntu:20.04:LTSqemu1:4.2-3ubuntu6.17, 1:4.0+dfsg-0ubuntu10, 1:4.2-1ubuntu1
Ubuntu:Pro:16.04:LTSqemu1:2.5+dfsg-1ubuntu5, *, *
Ubuntu:24.04:LTSqemu1:8.0.4+dfsg-1ubuntu5, 1:8.0.4+dfsg-1ubuntu4, 1:8.1.3+ds-1ubuntu2

Timeline

  • Jan 11, 2021 CVE Published
  • Jun 3, 2021 EPSS Score
  • Aug 5, 2021 EPSS Score
  • Oct 5, 2021 EPSS Score
  • Dec 5, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 6, 2022 EPSS Score
  • Jun 6, 2022 EPSS Score
  • Aug 7, 2022 EPSS Score
  • Oct 7, 2022 EPSS Score
  • Dec 7, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›