CVE-2020-35504: Debian Linux
Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.
A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 33 only
- Qemu Qemu: before 6.0.0 (fixed in 6.0.0)
Published 2021-05-28. Last modified 2026-06-17.