CVE-2020-35504: Debian Linux

Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.

A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 33 only
  • Qemu Qemu: before 6.0.0 (fixed in 6.0.0)

Published 2021-05-28. Last modified 2026-06-17.