The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | Jun 2, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade qemu-img | Jan 28, 2022 | Jun 2, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 2, 2021 |
| Suse | — | Upgrade xen-kmp-paeUpgrade xen-toolsUpgrade xen-libs-32bitUpgrade xen-tools-domuUpgrade xen-kmp-defaultUpgrade xenUpgrade xen-libsUpgrade xen-doc-html | Oct 25, 2019 | Oct 24, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 2, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub