---
cve: "CVE-2020-14394"
severity: "LOW"
cvss: 3.1
epss: "39%"
vendor: "n/a"
kev: false
exploited: false
published: "2022-08-17 21:15:07"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T07:33:45+02:00"
---

# CVE-2020-14394

> 3.1 LOW

## Beschreibung

An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

## Referenzen

- <https://bugzilla.redhat.com/show_bug.cgi?id=1908004>
- <https://gitlab.com/qemu-project/qemu/-/issues/646>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7J5IRXJYLELW7D43A75LOWRUE5EU54O/>
- <https://lists.debian.org/debian-lts-announce/2023/03/msg00013.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2020-14394) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
