ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-35503”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-35503
Published
2021-06-02
CVSS:
6.0
ShadowTrackr CVSS:
1.7
Summary:
A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dropping a SCSI request. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.