Out-of-bounds write in QEMU - CVE-2020-14364

 

Out-of-bounds write in QEMU - CVE-2020-14364

Published: August 24, 2020 / Updated: August 15, 2021


Vulnerability identifier: #VU45985
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14364
CWE-ID: CWE-787
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a boundary error within the USB emulator in QEMU. A remote user with access to guest operating system on the guest operating system can send specially crafted USB packets, trigger out-of-bounds write and execute arbitrary code on the host system.


Affected software

QEMU
Red Hat Virtualization Manager
Gentoo Linux
Amazon Linux AMI
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Opensuse
openEuler
Fedora
qemu-kvm (Red Hat package)
qemu-kvm-rhev (Red Hat package)
qemu (Debian package)
qemu (Alpine package)
redhat-release-virtualization-host (Red Hat package)
xen (Alpine package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
cockpit-ovirt (Red Hat package)
imgbased (Red Hat package)
qemu-system-aarch64 (Ubuntu package)
qemu-system-ppc (Ubuntu package)
qemu-system (Ubuntu package)
qemu-system-arm (Ubuntu package)
qemu-system-x86 (Ubuntu package)
qemu-system-misc (Ubuntu package)
qemu-system-sparc (Ubuntu package)
qemu-system-mips (Ubuntu package)
qemu (Ubuntu package)
qemu-guest-agent (Ubuntu package)
qemu-kvm (Ubuntu package)
qemu-block-extra (Ubuntu package)
qemu-system-s390x (Ubuntu package)
qemu-user-static (Ubuntu package)
qemu-user-binfmt (Ubuntu package)
qemu-utils (Ubuntu package)
qemu-system-common (Ubuntu package)
qemu-user (Ubuntu package)
qemu-kvm-ma (Red Hat package)
qemu
qemu-debuginfo
qemu-debugsource
qemu-guest-agent
qemu-seabios
qemu-img
qemu-help
qemu-system-x86-xen (Ubuntu package)
qemu-system-x86-microvm (Ubuntu package)
redhat-virtualization-host (Red Hat package)
xen
Red Hat Virtualization Host
Red Hat Virtualization
Red Hat Enterprise Linux Advanced Virtualization
Red Hat OpenStack
Red Hat OpenStack for IBM Power
BIG-IP LTM
BIG-IP PEM
BIG-IP AFM
BIG-IP Analytics
BIG-IP APM
BIG-IP ASM
BIG-IP FPS
BIG-IP GTM
BIG-IP
BIG-IP DDHD
BIG-IP SSLO
BIG-IP AAM
BIG-IP Link Controller
BIG-IP DNS
BIG-IP Advanced WAF
Juniper Junos Space

How to mitigate CVE-2020-14364

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

qemu-kvm (Red Hat package) - addressed in versions 0.12.1.2-2.415.el6_5.21, 0.12.1.2-2.448.el6_6.9, 0.12.1.2-2.506.el6_10.8, 1.5.3-105.el7_2.20, 1.5.3-126.el7_3.18, 1.5.3-141.el7_4.11, 1.5.3-160.el7_6.8, 1.5.3-167.el7_7.7, 1.5.3-175.el7_9.1
qemu-kvm-rhev (Red Hat package) - addressed in versions 2.12.0-33.el7_7.12, 2.12.0-48.el7_9.1
qemu (Debian package) - update to 1:3.1+dfsg-8+deb10u8
qemu (Alpine package) - update to 5.1.0-r1
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.11-1.el7ev, 4.4.2-1.el8ev
xen (Alpine package) - update to 4.13.1-r5
cockpit-ovirt (Red Hat package) - update to 0.14.11-1.el8ev
imgbased (Red Hat package) - update to 1.2.12-0.1.el8ev
qemu-system-aarch64 (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.46
qemu-system-ppc (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.46, 1:2.11+dfsg-1ubuntu7.32, 1:4.2-3ubuntu6.6
qemu-system (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.46, 1:2.11+dfsg-1ubuntu7.32, 1:4.2-3ubuntu6.6
qemu-system-arm (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.46, 1:2.11+dfsg-1ubuntu7.32, 1:4.2-3ubuntu6.6
qemu-system-x86 (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.46, 1:2.11+dfsg-1ubuntu7.32, 1:4.2-3ubuntu6.6
qemu-system-misc (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.46
qemu-system-sparc (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.46, 1:2.11+dfsg-1ubuntu7.32, 1:4.2-3ubuntu6.6
qemu-system-mips (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.46, 1:2.11+dfsg-1ubuntu7.32, 1:4.2-3ubuntu6.6
qemu (Ubuntu package) - addressed in versions 2.0.0+dfsg-2ubuntu1.47+esm1, 1:2.5+dfsg-5ubuntu10.46, 1:2.11+dfsg-1ubuntu7.32, 1:4.2-3ubuntu6.6
qemu-guest-agent (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.46
qemu-kvm (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.46
qemu-block-extra (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.46
qemu-system-s390x (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.46, 1:2.11+dfsg-1ubuntu7.32, 1:4.2-3ubuntu6.6
qemu-user-static (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.46
qemu-user-binfmt (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.46
qemu-utils (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.46
qemu-system-common (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.46
qemu-user (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.46
qemu-kvm-ma (Red Hat package) - addressed in versions 2.12.0-18.el7_6.7, 2.12.0-33.el7_7.4
qemu - update to 4.1.0-18
qemu-debuginfo - update to 4.1.0-18
qemu-debugsource - update to 4.1.0-18
qemu-guest-agent - update to 4.1.0-18
qemu-seabios - update to 4.1.0-18
qemu-img - update to 4.1.0-18
qemu-help - update to 4.1.0-18
qemu-system-x86-xen (Ubuntu package) - update to 1:4.2-3ubuntu6.6
qemu-system-x86-microvm (Ubuntu package) - update to 1:4.2-3ubuntu6.6
redhat-virtualization-host (Red Hat package) - addressed in versions 4.3.11-20200922.0.el7_9, 4.4.2-20200930.0.el8_2
xen - addressed in versions 4.12.3-4.fc31, 4.13.1-5.fc32
Juniper Junos Space - update to 21.2R1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins