CVE Vulnerabilities

CVE-2020-28916

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Dec 04, 2020 | Modified: Sep 30, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
2.5 LOW
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L
Ubuntu
MEDIUM

hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu 5.0.0 (including) 5.0.0 (including)
Red Hat Enterprise Linux 8 RedHat virt-devel:rhel-8040020210317013608.9f9e2e7e *
Red Hat Enterprise Linux 8 RedHat virt:rhel-8040020210317013608.9f9e2e7e *
Qemu Ubuntu bionic *
Qemu Ubuntu devel *
Qemu Ubuntu focal *
Qemu Ubuntu groovy *
Qemu Ubuntu trusty *
Qemu Ubuntu upstream *

References