Reachable Assertion in QEMU - CVE-2020-16092

 

Reachable Assertion in QEMU - CVE-2020-16092

Published: August 11, 2020


Vulnerability identifier: #VU44163
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16092
CWE-ID: CWE-617
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion when processing certain network packets on "e1000e" and "vmxnet3" devices in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c. A remote attacker on a guest operating system can send a specially crafted packet that will result in hypervisor crash.


Affected software

QEMU
Red Hat Virtualization Manager
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Opensuse
Ubuntu
qemu (Debian package)
qemu-kvm (Red Hat package)
qemu-system-mips (Ubuntu package)
qemu-system-aarch64 (Ubuntu package)
qemu-system-x86 (Ubuntu package)
qemu-system-sparc (Ubuntu package)
qemu-system-s390x (Ubuntu package)
qemu-system-ppc (Ubuntu package)
qemu-system-arm (Ubuntu package)
qemu-system (Ubuntu package)
qemu (Ubuntu package)
qemu-kvm-ma (Red Hat package)
qemu-kvm-rhev (Red Hat package)
qemu-system-x86-microvm (Ubuntu package)
qemu-system-x86-xen (Ubuntu package)
Red Hat Virtualization
Red Hat Enterprise Linux Advanced Virtualization
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Juniper Junos Space

How to mitigate CVE-2020-16092

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

qemu (Debian package) - update to 1:3.1+dfsg-8+deb10u8
qemu-kvm (Red Hat package) - update to 1.5.3-175.el7_9.3
qemu-system-mips (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-aarch64 (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.45
qemu-system-x86 (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-sparc (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-s390x (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-ppc (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-arm (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:4.2-3ubuntu6.4
qemu-system (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-kvm-ma (Red Hat package) - update to 2.12.0-48.el7_9.2
qemu-kvm-rhev (Red Hat package) - update to 2.12.0-48.el7_9.2
qemu-system-x86-microvm (Ubuntu package) - update to 1:4.2-3ubuntu6.4
qemu-system-x86-xen (Ubuntu package) - update to 1:4.2-3ubuntu6.4
Juniper Junos Space - update to 21.2R1

External References

Related Security Bulletins