CVE-2020-10761

MEDIUMCVSS 5/10EPSS 1.80%

Last modified

CVE-2020-10761 is a medium-severity vulnerability rated 5/10 on the CVSS scale. An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. EPSS estimates a 1.80% chance of exploitation in the next 30 days.

Description

An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.

Metrics

CVSS 3.1
5/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L

EPSS Probability
1.80%

75.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
QemuQemu< 5.0.1
RedhatEnterprise Linux8.0
OpensuseLeap15.2
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux18.04
CanonicalUbuntu Linux20.04

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-10761?
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
How severe is CVE-2020-10761?
CVE-2020-10761 has a CVSS score of 5/10 (MEDIUM severity). The EPSS model estimates a 1.80% probability of exploitation in the next 30 days.
How do I fix CVE-2020-10761?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-10761?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST