Out-of-bounds read in QEMU - CVE-2020-13362
Published: July 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in megasas_lookup_frame in hw/scsi/megasas.c. A local user on the guest operating system can pass specially crafted message with reply_queue_head field, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Gentoo Linux
Debian Linux
Ubuntu
Opensuse
openEuler
qemu-system-misc (Ubuntu package)
qemu-system-sparc (Ubuntu package)
qemu-system-mips (Ubuntu package)
qemu-system-ppc (Ubuntu package)
qemu (Ubuntu package)
qemu-system-x86 (Ubuntu package)
qemu-system-aarch64 (Ubuntu package)
qemu-system (Ubuntu package)
qemu-system-arm (Ubuntu package)
qemu-system-s390x (Ubuntu package)
qemu (Debian package)
qemu-guest-agent
qemu
qemu-debuginfo
qemu-debugsource
qemu-help
qemu-img
qemu-seabios
qemu-system-x86-microvm (Ubuntu package)
qemu-system-x86-xen (Ubuntu package)
How to mitigate CVE-2020-13362
qemu-system-sparc (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-mips (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-ppc (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-x86 (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-aarch64 (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.45
qemu-system (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-arm (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.45, 1:4.2-3ubuntu6.4
qemu-system-s390x (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu (Debian package) - update to 1:3.1+dfsg-8+deb10u6
qemu-guest-agent - update to 4.1.0-18
qemu - update to 4.1.0-18
qemu-debuginfo - update to 4.1.0-18
qemu-debugsource - update to 4.1.0-18
qemu-help - update to 4.1.0-18
qemu-img - update to 4.1.0-18
qemu-seabios - update to 4.1.0-18
qemu-system-x86-microvm (Ubuntu package) - update to 1:4.2-3ubuntu6.4
qemu-system-x86-xen (Ubuntu package) - update to 1:4.2-3ubuntu6.4
External References
- http://www.openwall.com/lists/oss-security/2020/05/28/2
- https://lists.debian.org/debian-lts-announce/2020/06/msg00032.html
- https://lists.gnu.org/archive/html/qemu-devel/2020-05/msg03131.html
- https://lists.gnu.org/archive/html/qemu-devel/2020-05/msg06250.html
- https://security.netapp.com/advisory/ntap-20200608-0003/
- https://security-tracker.debian.org/tracker/CVE-2020-13362
- https://www.debian.org/security/2020/dsa-4728