#VU73788 Infinite loop in QEMU - CVE-2020-14394
Published: March 17, 2023
QEMU
QEMU
Description
The vulnerability allows an attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. A privileged user on the guest OS can consume all available system resources and cause denial of service conditions of the QEMU process on the host.