A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Jun 4, 2020 |
| Oracle_linux | — | Upgrade qemu-system-x86-coreUpgrade qemuUpgrade ivshmem-toolsUpgrade qemu-block-rbdUpgrade qemu-commonUpgrade qemu-kvm-coreUpgrade qemu-kvmUpgrade qemu-system-aarch64Upgrade qemu-block-iscsiUpgrade qemu-block-glusterUpgrade qemu-imgUpgrade qemu-system-aarch64-coreUpgrade qemu-system-x86 | Feb 9, 2021 | Apr 2, 2020 |
| Suse | — | Upgrade qemu-hw-display-virtio-vgaUpgrade qemu-s390Upgrade qemu-ui-cursesUpgrade qemu-skibootUpgrade qemu-ksmUpgrade qemu-seabiosUpgrade qemu-armUpgrade qemu-ui-openglUpgrade qemu-block-curlUpgrade qemu-ui-gtkUpgrade qemu-block-iscsiUpgrade qemu-audio-alsaUpgrade qemu-x86Upgrade qemu-microvmUpgrade qemu-audio-paUpgrade qemu-block-rbdUpgrade qemu-vgabiosUpgrade qemu-block-sshUpgrade qemu-ui-spice-appUpgrade qemu-chardev-spiceUpgrade qemu-langUpgrade qemu-s390xUpgrade qemu-audio-spiceUpgrade qemu-ui-spice-coreUpgrade qemuUpgrade qemu-chardev-baumUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-sgabiosUpgrade qemu-hw-usb-redirectUpgrade qemu-guest-agentUpgrade qemu-kvmUpgrade qemu-toolsUpgrade qemu-ppcUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-ipxeUpgrade qemu-hw-display-qxl | Feb 4, 2022 | May 21, 2020 |
| Ubuntu | — | Upgrade qemuUpgrade qemu-system-armUpgrade qemu-system-mipsUpgrade qemu-systemUpgrade qemu-system-ppcUpgrade qemu-system-x86Upgrade qemu-system-s390xUpgrade qemu-system-sparc | May 22, 2020 | May 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub