Security Advisory

CVE-2020-25723

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-12-02 00:52:10
Last updated 2024-08-04 15:40:36
Assigner redhat
State PUBLISHED

Description

A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host, resulting in a denial of service.