CVE-2020-27617: Debian Linux
Medium severity, CVSS 6.5. EPSS: 2.6% chance of exploitation in the next 30 days.
eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.
Affected products
Published 2020-11-06. Last modified 2026-06-17.