hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest user or process could use this flaw to crash the QEMU process on the host, resulting in a denial of service or potential privileged code execution. This was fixed in commit 5519724a13664b43e225ca05351c60b4468e4555.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 22, 2024 | Jul 28, 2020 |
| Debian | — | Upgrade qemu | Jul 28, 2020 | Jul 28, 2020 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Aug 16, 2022 | Jul 28, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade qemu-img | Nov 3, 2020 | Jul 28, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade qemu-imgUpgrade qemu-kvm-commonUpgrade qemu-kvm | Sep 28, 2020 | Jul 28, 2020 |
| Oracle_linux | — | Upgrade ivshmem-toolsUpgrade qemu-system-x86-coreUpgrade qemu-system-aarch64Upgrade qemu-commonUpgrade qemuUpgrade qemu-block-rbdUpgrade qemu-block-glusterUpgrade qemu-block-iscsiUpgrade qemu-imgUpgrade qemu-kvm-coreUpgrade qemu-system-x86Upgrade qemu-system-aarch64-coreUpgrade qemu-kvm | Feb 9, 2021 | Jul 10, 2020 |
| Suse | — | Upgrade qemu-ppcUpgrade qemu-ui-spice-appUpgrade qemu-linux-userUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-toolsUpgrade qemuUpgrade kvmUpgrade qemu-audio-paUpgrade qemu-armUpgrade qemu-audio-ossUpgrade qemu-block-nfsUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-ui-cursesUpgrade qemu-guest-agentUpgrade qemu-block-glusterUpgrade qemu-hw-display-qxlUpgrade qemu-langUpgrade qemu-hw-usb-redirectUpgrade qemu-ui-openglUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-sgabiosUpgrade qemu-skibootUpgrade qemu-vhost-user-gpuUpgrade qemu-seabiosUpgrade qemu-audio-spiceUpgrade qemu-block-sshUpgrade qemu-ui-spice-coreUpgrade qemu-block-dmgUpgrade qemu-s390xUpgrade qemu-ipxeUpgrade qemu-block-iscsiUpgrade qemu-vgabiosUpgrade qemu-chardev-spiceUpgrade qemu-ui-gtkUpgrade qemu-extraUpgrade qemu-audio-sdlUpgrade qemu-audio-alsaUpgrade qemu-microvmUpgrade qemu-block-curlUpgrade qemu-testsuiteUpgrade qemu-block-rbdUpgrade qemu-ui-sdlUpgrade qemu-x86Upgrade qemu-chardev-baumUpgrade qemu-ksmUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-s390Upgrade qemu-kvm | Sep 25, 2020 | Jul 28, 2020 |
| Ubuntu | — | Upgrade qemu-systemUpgrade qemu-user (Ubuntu Pro)Upgrade qemu-keymaps (Ubuntu Pro)Upgrade qemu-system (Ubuntu Pro)Upgrade qemu (Ubuntu Pro)Upgrade qemu-system-armUpgrade qemu-system-sparc (Ubuntu Pro)Upgrade qemu-system-sparcUpgrade qemu-kvm (Ubuntu Pro)Upgrade qemu-system-x86Upgrade qemu-utils (Ubuntu Pro)Upgrade qemu-system-mips (Ubuntu Pro)Upgrade qemu-system-mipsUpgrade qemu-system-aarch64 (Ubuntu Pro)Upgrade qemu-system-x86-xenUpgrade qemu-system-ppcUpgrade qemu-user-static (Ubuntu Pro)Upgrade qemu-system-x86 (Ubuntu Pro)Upgrade qemu-system-common (Ubuntu Pro)Upgrade qemu-system-misc (Ubuntu Pro)Upgrade qemu-system-arm (Ubuntu Pro)Upgrade qemu-guest-agent (Ubuntu Pro)Upgrade qemu-system-ppc (Ubuntu Pro)Upgrade qemu-common (Ubuntu Pro)Upgrade qemu-system-s390xUpgrade qemuUpgrade qemu-system-aarch64Upgrade qemu-system-x86-microvm | Aug 20, 2020 | Jul 28, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub