An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in modesensepage() if the 'page' argument was set to MODEPAGEALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
{
"unresolved_ranges": [
{
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"last_affected": "9.0"
},
{
"last_affected": "10.0"
}
],
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:codeready_linux_builder",
"extracted_events": [
{
"last_affected": "8.0"
}
],
"cpes": [
"cpe:2.3:a:redhat:codeready_linux_builder:8.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:codeready_linux_builder_for_ibm_z_systems",
"extracted_events": [
{
"last_affected": "8.0"
}
],
"cpes": [
"cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems:8.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:codeready_linux_builder_for_power_little_endian",
"extracted_events": [
{
"last_affected": "8.0"
}
],
"cpes": [
"cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian:8.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:enterprise_linux",
"extracted_events": [
{
"last_affected": "8.0"
}
],
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:enterprise_linux_advanced_virtualization_eus",
"extracted_events": [
{
"last_affected": "8.4"
}
],
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_advanced_virtualization_eus:8.4:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:enterprise_linux_for_ibm_z_systems",
"extracted_events": [
{
"last_affected": "8.0"
}
],
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:enterprise_linux_for_power_little_endian",
"extracted_events": [
{
"last_affected": "8.0"
}
],
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:openstack",
"extracted_events": [
{
"last_affected": "10"
},
{
"last_affected": "13"
}
],
"cpes": [
"cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
}
]
}