CVE Vulnerabilities

CVE-2020-24165

Published: Aug 28, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third parties.

Affected Software

NameVendorStart VersionEnd Version
QemuQemu4.2.0 (including)4.2.0 (including)
QemuUbuntubionic*
QemuUbuntuesm-infra/focal*
QemuUbuntufocal*
QemuUbuntutrusty*
QemuUbuntuupstream*
QemuUbuntuxenial*

References