CVE-2020-35504: Null Pointer Dereference
A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Other sources
A NULL pointer dereference issue was found in the SCSI emulation support of QEMU. It could occur in the scsireqcontinue() function in hw/scsi/scsi-bus.c while handling the 'Information Transfer' command (CMDTI) of the am53c974 SCSI host bus adapter. A privileged guest user may abuse this issue to crash the QEMU process on the host, resulting in a denial of service condition.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-35504?
CVE-2020-35504 is a vulnerability found in the SCSI emulation support of QEMU.
How does CVE-2020-35504 affect systems?
CVE-2020-35504 allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
How severe is CVE-2020-35504?
CVE-2020-35504 has a severity rating of medium.
Which versions of QEMU are affected by CVE-2020-35504?
QEMU versions before 6.0.0 are affected by CVE-2020-35504.
How can I fix CVE-2020-35504?
The recommended fix for CVE-2020-35504 is to update QEMU to version 6.0.0 or later.