In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host, resulting in a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 3.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Sep 8, 2020 | Aug 31, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade qemu-img | Feb 8, 2021 | Aug 31, 2020 |
| Oracle_linux | — | Upgrade qemu-imgUpgrade qemu-kvm-coreUpgrade qemu-commonUpgrade qemuUpgrade qemu-system-aarch64Upgrade qemu-system-x86Upgrade qemu-block-rbdUpgrade qemu-system-x86-coreUpgrade qemu-block-glusterUpgrade qemu-kvmUpgrade ivshmem-toolsUpgrade qemu-block-iscsiUpgrade qemu-system-aarch64-core | Feb 9, 2021 | Dec 23, 2019 |
| Suse | — | Upgrade qemu-block-dmgUpgrade qemu-audio-sdlUpgrade qemu-x86Upgrade qemu-sgabiosUpgrade qemu-s390Upgrade qemu-extraUpgrade qemu-ui-sdlUpgrade qemu-ksmUpgrade qemu-block-curlUpgrade qemu-vhost-user-gpuUpgrade qemu-testsuiteUpgrade qemu-audio-ossUpgrade qemu-seabiosUpgrade qemu-audio-alsaUpgrade qemu-ui-cursesUpgrade qemu-block-iscsiUpgrade qemu-audio-paUpgrade qemu-vgabiosUpgrade qemu-ppcUpgrade qemu-block-sshUpgrade qemu-armUpgrade qemu-ui-gtkUpgrade qemu-microvmUpgrade qemu-toolsUpgrade qemu-ui-spice-appUpgrade qemu-langUpgrade qemu-guest-agentUpgrade qemuUpgrade qemu-block-glusterUpgrade qemu-kvmUpgrade kvmUpgrade qemu-block-rbdUpgrade qemu-ipxeUpgrade qemu-linux-userUpgrade qemu-block-nfs | Apr 17, 2021 | Aug 19, 2020 |
| Ubuntu | — | Upgrade qemu-system-ppcUpgrade qemu-system-aarch64Upgrade qemu-systemUpgrade qemu-system-x86-microvmUpgrade qemu-system-mipsUpgrade qemu-system-sparcUpgrade qemuUpgrade qemu-common (Ubuntu Pro)Upgrade qemu-system (Ubuntu Pro)Upgrade qemu-system-x86Upgrade qemu-system-common (Ubuntu Pro)Upgrade qemu-system-sparc (Ubuntu Pro)Upgrade qemu-user (Ubuntu Pro)Upgrade qemu-keymaps (Ubuntu Pro)Upgrade qemu-system-ppc (Ubuntu Pro)Upgrade qemu-kvm (Ubuntu Pro)Upgrade qemu-system-x86-xenUpgrade qemu-system-aarch64 (Ubuntu Pro)Upgrade qemu-utils (Ubuntu Pro)Upgrade qemu-system-x86 (Ubuntu Pro)Upgrade qemu-system-misc (Ubuntu Pro)Upgrade qemu (Ubuntu Pro)Upgrade qemu-system-s390xUpgrade qemu-system-arm (Ubuntu Pro)Upgrade qemu-system-mips (Ubuntu Pro)Upgrade qemu-system-armUpgrade qemu-guest-agent (Ubuntu Pro)Upgrade qemu-user-static (Ubuntu Pro) | Aug 20, 2020 | Aug 19, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub