Stack-based buffer overflow in QEMU - CVE-2020-15863
Published: July 24, 2020
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system with elevated privileges.
The vulnerability exists due to a boundary error when processing packets in xgmac_enet_send() in hw/net/xgmac.c. A local user on the guest operating system can send a specially crafted request to the application, trigger stack-based buffer overflow and execute arbitrary code on the target system with elevated privileges.
Affected software
qemu (Debian package)
qemu-system-aarch64 (Ubuntu package)
qemu-system-x86 (Ubuntu package)
qemu (Ubuntu package)
qemu-system-sparc (Ubuntu package)
qemu-system (Ubuntu package)
qemu-system-arm (Ubuntu package)
qemu-system-s390x (Ubuntu package)
qemu-system-mips (Ubuntu package)
qemu-system-ppc (Ubuntu package)
qemu-system-x86-microvm (Ubuntu package)
qemu-system-x86-xen (Ubuntu package)
Opensuse
Ubuntu
How to mitigate CVE-2020-15863
qemu-system-aarch64 (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.45
qemu-system-x86 (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-sparc (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-arm (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:4.2-3ubuntu6.4
qemu-system-s390x (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-mips (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-ppc (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-x86-microvm (Ubuntu package) - update to 1:4.2-3ubuntu6.4
qemu-system-x86-xen (Ubuntu package) - update to 1:4.2-3ubuntu6.4