CVE-2020-35503: Null Pointer Dereference
A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasascommandcancelled() callback function while dropping a SCSI request. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Other sources
A NULL pointer dereference issue was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU. It could occur in the megasascommandcancelled() callback function in hw/scsi/megasas.c while dropping a SCSI request. A privileged guest user may exploit this issue to crash the QEMU process on the host, resulting in a denial of service condition.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35503?
CVE-2020-35503 is considered a moderate severity vulnerability as it can lead to a denial of service due to a NULL pointer dereference.
How do I fix CVE-2020-35503?
To fix CVE-2020-35503, update QEMU to version 6.0.1 or later, which addresses this specific vulnerability.
Which versions of QEMU are affected by CVE-2020-35503?
CVE-2020-35503 affects QEMU versions up to and including 6.0.0.
Can a privileged guest user exploit CVE-2020-35503?
Yes, a privileged guest user can exploit CVE-2020-35503 to crash the QEMU process.
What systems are impacted by CVE-2020-35503?
CVE-2020-35503 impacts QEMU and Fedora 33, which runs the affected versions of QEMU.