ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-14394

An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
An official patch is available. Apply the patch as soon as possible.
3.2
CVSS
0.9
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorLocal
ComplexityLow
RequirementsPresent
PrivilegesHigh
User InteractionNone
Threat
Exploit MaturityPoC
Vulnerable System
ConfidentialityNone
IntegrityNone
AvailabilityLow
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusOfficial Patch

Change Log
DateSourceChangesScore
2026-07-21PoCE: U→P0.2 → 0.9
2026-07-21nvdAV: P→L, AC: H→L, UI: A→N, VA: N→L0.0 → 0.2
2026-07-21nvdpatch: Unavailable→Official Patch0.0 → 0.0
2026-07-21cve.orginitial, patch: Unavailable0.0

Affected Software
VendorProductVersion
fedoraprojectextra_packages_for_enterprise_linux7.0
fedoraprojectfedora33
fedoraprojectfedora37
n/aQEMUQEMU 6.1.50
qemuqemu6.1.50
redhatenterprise_linux5.0
redhatenterprise_linux6.0
redhatenterprise_linux7.0
redhatenterprise_linux8.0
redhatenterprise_linux9.0
redhatopenstack_platform10.0
redhatopenstack_platform13.0
Published: 2022-08-17