hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
CVSS Details
- CVSS 3.1 Base Score: 5.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Apr 6, 2020 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Jun 15, 2020 | Apr 6, 2020 |
| Oracle_linux | — | Upgrade qemu-system-aarch64-coreUpgrade qemu-block-iscsiUpgrade qemu-system-x86Upgrade qemu-imgUpgrade qemu-block-glusterUpgrade qemu-kvm-coreUpgrade qemuUpgrade qemu-system-x86-coreUpgrade ivshmem-toolsUpgrade qemu-system-aarch64Upgrade qemu-block-rbdUpgrade qemu-kvmUpgrade qemu-common | Feb 9, 2021 | Feb 11, 2020 |
| Suse | — | Upgrade qemu-armUpgrade qemu-audio-alsaUpgrade qemu-skibootUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-ppcUpgrade qemu-block-iscsiUpgrade qemu-x86Upgrade qemu-toolsUpgrade qemu-seabiosUpgrade qemu-sgabiosUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-vgabiosUpgrade qemu-ui-gtkUpgrade qemu-hw-display-qxlUpgrade qemu-audio-paUpgrade qemu-block-curlUpgrade qemu-microvmUpgrade qemu-ui-spice-coreUpgrade qemuUpgrade qemu-ui-cursesUpgrade qemu-guest-agentUpgrade qemu-hw-usb-redirectUpgrade qemu-kvmUpgrade qemu-audio-spiceUpgrade qemu-chardev-spiceUpgrade qemu-block-sshUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-ipxeUpgrade qemu-ui-spice-appUpgrade qemu-ksmUpgrade qemu-ui-openglUpgrade qemu-s390xUpgrade qemu-block-rbdUpgrade qemu-s390Upgrade qemu-langUpgrade qemu-chardev-baumUpgrade qemu-hw-display-virtio-gpu | Feb 4, 2022 | Apr 6, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub