Loop with Unreachable Exit Condition ('Infinite Loop') Affecting qemu-guest-agent package, versions *
Snyk CVSS
Attack Complexity
Low
Privileges Required
High
Scope
Changed
Threat Intelligence
EPSS
0.05% (20th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CENTOS7-QEMUGUESTAGENT-2005723
- published 26 Jul 2021
- disclosed 15 Dec 2020
Introduced: 15 Dec 2020
CVE-2020-14394 Open this link in a new tabHow to fix?
There is no fixed version for Centos:7
qemu-guest-agent
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream qemu-guest-agent
package and not the qemu-guest-agent
package as distributed by Centos
.
See How to fix?
for Centos:7
relevant fixed versions and status.
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
References
- https://access.redhat.com/security/cve/CVE-2020-14394
- https://bugzilla.redhat.com/show_bug.cgi?id=1908004
- https://gitlab.com/qemu-project/qemu/-/issues/646
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I7J5IRXJYLELW7D43A75LOWRUE5EU54O/
- https://lists.debian.org/debian-lts-announce/2023/03/msg00013.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7J5IRXJYLELW7D43A75LOWRUE5EU54O/