An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 22, 2024 | Oct 16, 2020 |
| Debian | — | Upgrade qemu | May 15, 2025 | Oct 16, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 16, 2020 |
| Suse | — | Upgrade qemu-audio-sdlUpgrade qemu-x86Upgrade qemu-block-dmgUpgrade qemu-ui-sdlUpgrade qemu-sgabiosUpgrade qemu-extraUpgrade qemu-ui-cursesUpgrade qemu-linux-userUpgrade qemu-audio-paUpgrade qemu-block-nfsUpgrade qemu-microvmUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-kvmUpgrade qemu-vgabiosUpgrade qemu-chardev-baumUpgrade qemu-hw-display-qxlUpgrade qemuUpgrade qemu-block-curlUpgrade qemu-guest-agentUpgrade qemu-skibootUpgrade qemu-block-rbdUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-vhost-user-gpuUpgrade qemu-langUpgrade qemu-chardev-spiceUpgrade qemu-ui-spice-coreUpgrade qemu-seabiosUpgrade qemu-block-sshUpgrade qemu-ipxeUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-ui-spice-appUpgrade qemu-s390Upgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-ksmUpgrade qemu-armUpgrade qemu-audio-spiceUpgrade qemu-hw-usb-redirectUpgrade qemu-block-glusterUpgrade qemu-toolsUpgrade qemu-ui-openglUpgrade qemu-ui-gtkUpgrade qemu-audio-alsaUpgrade qemu-ppcUpgrade qemu-testsuiteUpgrade qemu-s390xUpgrade qemu-block-iscsi | Oct 14, 2020 | Oct 7, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub