CVE-2020-10761: Canonical Ubuntu Linux
Medium severity, CVSS 5.0. EPSS: 1.8% chance of exploitation in the next 30 days.
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 20.04 only
- Opensuse Leap: version 15.2 only
- Qemu Qemu: before 5.0.1 (fixed in 5.0.1)
- Red Hat Enterprise Linux: version 8.0 only
Published 2020-06-09. Last modified 2026-06-17.