Out-of-bounds write in QEMU - CVE-2020-13765

 

Out-of-bounds write in QEMU - CVE-2020-13765

Published: July 24, 2020


Vulnerability identifier: #VU31806
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13765
CWE-ID: CWE-787
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in rom_copy() in hw/core/loader.c. A local user on the guest operating system can create a specially data to the application, trigger out-of-bounds write and execute arbitrary code on the host system.


Affected software

QEMU
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
CentOS
Red Hat Enterprise Linux Server
Ubuntu
openEuler
qemu-system (Ubuntu package)
qemu-system-misc (Ubuntu package)
qemu-system-ppc (Ubuntu package)
qemu-system-mips (Ubuntu package)
qemu-system-s390x (Ubuntu package)
qemu-system-sparc (Ubuntu package)
qemu-system-arm (Ubuntu package)
qemu-system-x86 (Ubuntu package)
qemu (Ubuntu package)
qemu-system-aarch64 (Ubuntu package)
qemu-system-common (Ubuntu package)
qemu-kvm (Red Hat package)
qemu
qemu-seabios
qemu-debuginfo
qemu-img
qemu-debugsource
qemu-guest-agent
qemu-help
qemu-system-x86-microvm (Ubuntu package)
qemu-system-x86-xen (Ubuntu package)
qemu-system-xen (Ubuntu package)
Juniper Junos Space

How to mitigate CVE-2020-13765

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

qemu-system (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4, 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24, 1:8.2.2+ds-0ubuntu1.4, 1:9.0.2+ds-4ubuntu5.1
qemu-system-misc (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24, 1:8.2.2+ds-0ubuntu1.4, 1:9.0.2+ds-4ubuntu5.1
qemu-system-ppc (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4, 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24, 1:8.2.2+ds-0ubuntu1.4, 1:9.0.2+ds-4ubuntu5.1
qemu-system-mips (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4, 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24, 1:8.2.2+ds-0ubuntu1.4, 1:9.0.2+ds-4ubuntu5.1
qemu-system-s390x (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4, 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24, 1:8.2.2+ds-0ubuntu1.4, 1:9.0.2+ds-4ubuntu5.1
qemu-system-sparc (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4, 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24, 1:8.2.2+ds-0ubuntu1.4, 1:9.0.2+ds-4ubuntu5.1
qemu-system-arm (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.5+dfsg-5ubuntu10.45, 1:4.2-3ubuntu6.4, 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24, 1:8.2.2+ds-0ubuntu1.4, 1:9.0.2+ds-4ubuntu5.1
qemu-system-x86 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4, 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24, 1:8.2.2+ds-0ubuntu1.4, 1:9.0.2+ds-4ubuntu5.1
qemu (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4, 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24
qemu-system-aarch64 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.5+dfsg-5ubuntu10.45
qemu-system-common (Ubuntu package) - update to Ubuntu Pro
qemu-kvm (Red Hat package) - update to 1.5.3-175.el7_9.3
qemu - update to 4.1.0-18
qemu-seabios - update to 4.1.0-18
qemu-debuginfo - update to 4.1.0-18
qemu-img - update to 4.1.0-18
qemu-debugsource - update to 4.1.0-18
qemu-guest-agent - update to 4.1.0-18
qemu-help - update to 4.1.0-18
qemu-system-x86-microvm (Ubuntu package) - addressed in versions 1:4.2-3ubuntu6.4, 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24
qemu-system-x86-xen (Ubuntu package) - addressed in versions 1:4.2-3ubuntu6.4, 1:4.2-3ubuntu6.30, 1:6.2+dfsg-2ubuntu6.24, 1:8.2.2+ds-0ubuntu1.4, 1:9.0.2+ds-4ubuntu5.1
qemu-system-xen (Ubuntu package) - addressed in versions 1:8.2.2+ds-0ubuntu1.4, 1:9.0.2+ds-4ubuntu5.1
Juniper Junos Space - update to 21.2R1

External References

Related Security Bulletins