CVE-2020-16092: Canonical Ubuntu Linux
Low severity, CVSS 3.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 20.04 only
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Opensuse Leap: version 15.2 only
- Qemu Qemu: up to and including 5.0.0
Published 2020-08-11. Last modified 2026-06-17.