An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 22, 2024 | Oct 16, 2020 |
| Debian | — | Upgrade qemu | May 15, 2025 | Oct 16, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 16, 2020 |
| Suse | — | Upgrade qemu-microvmUpgrade qemu-block-nfsUpgrade qemu-audio-sdlUpgrade qemu-hw-display-qxlUpgrade qemu-linux-userUpgrade qemu-x86Upgrade qemu-block-dmgUpgrade qemu-ui-sdlUpgrade qemuUpgrade qemu-vgabiosUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-chardev-baumUpgrade qemu-kvmUpgrade qemu-ui-cursesUpgrade qemu-audio-paUpgrade qemu-extraUpgrade qemu-sgabiosUpgrade qemu-block-sshUpgrade qemu-s390Upgrade qemu-seabiosUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-vhost-user-gpuUpgrade qemu-ipxeUpgrade qemu-block-rbdUpgrade qemu-skibootUpgrade qemu-ppcUpgrade qemu-s390xUpgrade qemu-armUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-block-glusterUpgrade qemu-block-iscsiUpgrade qemu-chardev-spiceUpgrade qemu-block-curlUpgrade qemu-langUpgrade qemu-guest-agentUpgrade qemu-hw-usb-redirectUpgrade qemu-audio-spiceUpgrade qemu-ksmUpgrade qemu-testsuiteUpgrade qemu-toolsUpgrade qemu-ui-spice-coreUpgrade qemu-ui-openglUpgrade qemu-ui-gtkUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-ui-spice-appUpgrade qemu-audio-alsa | Oct 14, 2020 | Oct 7, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub