hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configuration space.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 22, 2024 | Jun 4, 2020 |
| Debian | — | Upgrade qemu | Jul 30, 2024 | Jun 4, 2020 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Nov 12, 2020 | Jun 4, 2020 |
| Oracle_linux | — | Upgrade qemu-system-x86-coreUpgrade ivshmem-toolsUpgrade qemu-commonUpgrade qemu-kvmUpgrade qemu-system-aarch64-coreUpgrade qemu-system-x86Upgrade qemu-block-rbdUpgrade qemuUpgrade qemu-system-aarch64Upgrade qemu-kvm-coreUpgrade qemu-imgUpgrade qemu-block-glusterUpgrade qemu-block-iscsi | Feb 9, 2021 | Jun 3, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 4, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub