eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.
https://security.netapp.com/advisory/ntap-20201202-0002/
https://lists.nongnu.org/archive/html/qemu-devel/2020-10/msg05731.html
https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html
https://lists.debian.org/debian-lts-announce/2020/11/msg00047.html
http://www.openwall.com/lists/oss-security/2020/11/02/1