Buffer overflow in QEMU - CVE-2019-15034
Published: April 28, 2020
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the hw/display/bochs-display.c in QEMU due to application does not ensure a sufficient PCI config space allocation. A local user can trigger a buffer overflow and escalate privileges on the system.
Affected software
qemu (Ubuntu package)
qemu (Debian package)
Opensuse
How to mitigate CVE-2019-15034
qemu (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.44, 1:2.11+dfsg-1ubuntu7.26, 1:4.0+dfsg-0ubuntu9.6, 1:4.2-3ubuntu6.1
qemu (Debian package) - update to 1:3.1+dfsg-8+deb10u5