REDHAT-BUG-1910346: Null Pointer Dereference
A NULL pointer dereference issue was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU. It could occur in the megasascommandcancelled() callback function in hw/scsi/megasas.c while dropping a SCSI request. A privileged guest user may exploit this issue to crash the QEMU process on the host, resulting in a denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1910346?
The severity of REDHAT-BUG-1910346 is high as it allows a privileged guest user to crash the QEMU process.
How do I fix REDHAT-BUG-1910346?
To fix REDHAT-BUG-1910346, users should apply the latest patches provided by QEMU.
What impact does REDHAT-BUG-1910346 have on users?
The impact of REDHAT-BUG-1910346 is that it can lead to a denial of service by crashing the QEMU process.
Who is affected by REDHAT-BUG-1910346?
Any environments running the affected versions of QEMU with the megasas-gen2 SCSI host bus adapter are at risk from REDHAT-BUG-1910346.
Is there a workaround for REDHAT-BUG-1910346?
Currently, the only recommended approach for REDHAT-BUG-1910346 is to update to a patched version of QEMU.