hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
CVSS Details
- CVSS 3.1 Base Score: 5.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Apr 6, 2020 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Jun 15, 2020 | Apr 6, 2020 |
| Oracle_linux | — | Upgrade qemu-system-x86-coreUpgrade qemu-system-aarch64Upgrade ivshmem-toolsUpgrade qemu-commonUpgrade qemu-block-rbdUpgrade qemuUpgrade qemu-kvmUpgrade qemu-system-aarch64-coreUpgrade qemu-imgUpgrade qemu-system-x86Upgrade qemu-kvm-coreUpgrade qemu-block-glusterUpgrade qemu-block-iscsi | Feb 9, 2021 | Feb 11, 2020 |
| Suse | — | Upgrade qemu-kvmUpgrade qemu-ui-openglUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-ui-spice-appUpgrade qemu-s390Upgrade qemu-audio-spiceUpgrade qemu-block-rbdUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-ipxeUpgrade qemu-langUpgrade qemu-chardev-spiceUpgrade qemu-s390xUpgrade qemu-chardev-baumUpgrade qemu-ksmUpgrade qemu-block-sshUpgrade qemu-armUpgrade qemu-audio-alsaUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-sgabiosUpgrade qemu-block-curlUpgrade qemu-microvmUpgrade qemu-vgabiosUpgrade qemu-hw-display-qxlUpgrade qemu-ui-gtkUpgrade qemu-seabiosUpgrade qemu-block-iscsiUpgrade qemu-guest-agentUpgrade qemu-ui-spice-coreUpgrade qemu-audio-paUpgrade qemu-ui-cursesUpgrade qemu-toolsUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-hw-usb-redirectUpgrade qemu-skibootUpgrade qemuUpgrade qemu-x86Upgrade qemu-ppc | Feb 4, 2022 | Apr 6, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub