Heap-based buffer overflow in QEMU - CVE-2020-25085

 

Heap-based buffer overflow in QEMU - CVE-2020-25085

Published: September 25, 2020 / Updated: October 20, 2022


Vulnerability identifier: #VU47247
CSH Severity: Medium
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25085
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

QEMU
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
qemu-ipxe
qemu-vgabios
qemu-seabios
qemu-audio-sdl-debuginfo
qemu-guest-agent-debuginfo
qemu-block-rbd
qemu-block-curl-debuginfo
qemu-ui-gtk-debuginfo
qemu-ui-sdl-debuginfo
qemu-audio-pa-debuginfo
qemu-block-curl
qemu-guest-agent
qemu-audio-pa
qemu-debugsource
qemu-audio-alsa-debuginfo
qemu-block-iscsi
qemu-block-ssh
qemu-block-rbd-debuginfo
qemu-audio-oss-debuginfo
qemu-block-iscsi-debuginfo
qemu-s390
qemu-s390-debuginfo
qemu-ppc-debuginfo
qemu-ppc
qemu-x86
qemu-kvm
qemu-arm
qemu-arm-debuginfo
qemu-tools-debuginfo
qemu
qemu-tools
qemu-audio-alsa
qemu-lang
qemu-ui-gtk
qemu-ui-curses-debuginfo
qemu-ui-sdl
qemu-block-ssh-debuginfo
qemu-ui-curses
qemu-audio-oss
qemu-audio-sdl
qemu-debuginfo
qemu-x86-debuginfo
qemu-sgabios

How to mitigate CVE-2020-25085

Install update from vendor's website.

qemu-ipxe - addressed in versions 1.0.0+-66.1, 1.0.0+-150100.80.43.2
qemu-vgabios - addressed in versions 1.12.0_0_ga698c89-66.1, 1.12.0_0_ga698c89-150100.80.43.2
qemu-seabios - addressed in versions 1.12.0_0_ga698c89-66.1, 1.12.0_0_ga698c89-150100.80.43.2
qemu-audio-sdl-debuginfo - update to 3.1.1.1-66.1
qemu-guest-agent-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-block-rbd - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-block-curl-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-ui-gtk-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-ui-sdl-debuginfo - update to 3.1.1.1-66.1
qemu-audio-pa-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-block-curl - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-guest-agent - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-audio-pa - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-debugsource - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-audio-alsa-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-block-iscsi - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-block-ssh - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-block-rbd-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-audio-oss-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-block-iscsi-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-s390 - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-s390-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-ppc-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-ppc - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-x86 - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-kvm - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-arm - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-arm-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-tools-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-tools - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-audio-alsa - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-lang - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-ui-gtk - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-ui-curses-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-ui-sdl - update to 3.1.1.1-66.1
qemu-block-ssh-debuginfo - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-ui-curses - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-audio-oss - addressed in versions 3.1.1.1-66.1, 3.1.1.1-150100.80.43.2
qemu-audio-sdl - update to 3.1.1.1-66.1
qemu-debuginfo - update to 3.1.1.1-150100.80.43.2
qemu-x86-debuginfo - update to 3.1.1.1-150100.80.43.2
qemu-sgabios - addressed in versions 8-66.1, 8-150100.80.43.2

External References

Related Security Bulletins