Integer overflow in QEMU - CVE-2020-11869
Published: May 5, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow within the implementation of ATI VGA emulation in ati_2d_blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati_mm_write() callback.. A remote attacker on the guest operating system can abuse this flaw to crash the QEMU process, resulting in a denial of service.
Affected software
qemu (Ubuntu package)
How to mitigate CVE-2020-11869
qemu (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.44, 1:2.11+dfsg-1ubuntu7.26, 1:4.0+dfsg-0ubuntu9.6, 1:4.2-3ubuntu6.1