A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Jun 4, 2020 |
| Oracle_linux | — | Upgrade ivshmem-toolsUpgrade qemu-commonUpgrade qemu-kvm-coreUpgrade qemu-system-x86-coreUpgrade qemu-block-rbdUpgrade qemuUpgrade qemu-system-aarch64Upgrade qemu-kvmUpgrade qemu-block-iscsiUpgrade qemu-system-aarch64-coreUpgrade qemu-imgUpgrade qemu-block-glusterUpgrade qemu-system-x86 | Feb 9, 2021 | Apr 2, 2020 |
| Suse | — | Upgrade qemu-vgabiosUpgrade qemu-kvmUpgrade qemu-s390xUpgrade qemu-block-rbdUpgrade qemu-block-sshUpgrade qemu-ui-spice-appUpgrade qemu-hw-display-qxlUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-guest-agentUpgrade qemu-ipxeUpgrade qemu-ui-spice-coreUpgrade qemu-audio-spiceUpgrade qemu-toolsUpgrade qemu-langUpgrade qemuUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-chardev-spiceUpgrade qemu-hw-usb-redirectUpgrade qemu-chardev-baumUpgrade qemu-sgabiosUpgrade qemu-ppcUpgrade qemu-audio-paUpgrade qemu-seabiosUpgrade qemu-ui-openglUpgrade qemu-skibootUpgrade qemu-block-curlUpgrade qemu-ui-cursesUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-ksmUpgrade qemu-s390Upgrade qemu-armUpgrade qemu-block-iscsiUpgrade qemu-ui-gtkUpgrade qemu-x86Upgrade qemu-audio-alsaUpgrade qemu-microvm | Feb 4, 2022 | May 21, 2020 |
| Ubuntu | — | Upgrade qemu-system-s390xUpgrade qemu-system-sparcUpgrade qemu-system-x86Upgrade qemuUpgrade qemu-systemUpgrade qemu-system-mipsUpgrade qemu-system-ppcUpgrade qemu-system-arm | May 22, 2020 | May 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub