CVE-2020-14364
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets...
- Published
- Aug 31, 2020
- Updated
- Aug 4, 2024
- Assigning CNA
- redhat
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:LLow · next 30 days
- Percentile
- 92.4%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of service, or the potential execution of arbitrary code with the privileges of the QEMU process on the host.
Sources
2- CVE-2020-14364Exploit
C exploit for CVE-2020-14364 targeting a specific vulnerability in QEMU USB redirector, enabling local privilege escalation.
- CVE-2020-14364Exploit
Ring0 exploit for CVE-2020-14364, providing kernel-level privilege escalation for penetration testing and vulnerability validation on affected systems.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.