Heap-based buffer overflow in QEMU - CVE-2020-1711

 

Heap-based buffer overflow in QEMU - CVE-2020-1711

Published: February 21, 2020


Vulnerability identifier: #VU25510
CSH Severity: Medium
CVSS v4: 6.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1711
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a boundary error in the way the iSCSI Block driver handles a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an "iscsi_co_block_status()" routine. A remote authenticated attacker can trigger heap-based buffer overflow and cause a denial of service condition or potentially execute arbitrary code with privileges of the QEMU process on the host.



Affected software

QEMU
Red Hat Virtualization Manager
Gentoo Linux
Debian Linux
Arch Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Opensuse
qemu-kvm-rhev (Red Hat package)
qemu (Debian package)
qemu-kvm-ma (Red Hat package)
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat OpenStack
Red Hat OpenStack for IBM Power

How to mitigate CVE-2020-1711

Install updates from vendor's website.

QEMU - update to 4.2.1
qemu-kvm-rhev (Red Hat package) - addressed in versions 2.12.0-33.el7_7.10, 2.12.0-44.el7
qemu (Debian package) - addressed in versions 1:2.8+dfsg-6+deb9u9, 1:3.1+dfsg-8+deb10u4
qemu-kvm-ma (Red Hat package) - addressed in versions 2.10.0-21.el7_5.5, 2.12.0-33.el7_7.3, 2.12.0-44.el7

External References

Related Security Bulletins