QEMU xHCI infinite loop privileged guest DOS
CVE-2020-14394 Published on August 17, 2022

An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

Vendor Advisory NVD

Weakness Type

What is an Infinite Loop Vulnerability?

The program contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop. If the loop can be influenced by an attacker, this weakness could allow attackers to consume excessive resources such as CPU or memory.

CVE-2020-14394 has been classified to as an Infinite Loop vulnerability or weakness.


Products Associated with CVE-2020-14394

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-14394 are published in these products:

 
 
 
 
 
 

Exploit Probability

EPSS
0.03%
Percentile
6.62%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.