Out-of-bounds read in QEMU - CVE-2020-29443

 

Out-of-bounds read in QEMU - CVE-2020-29443

Published: January 26, 2021 / Updated: January 26, 2021


Vulnerability identifier: #VU50042
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-29443
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ide_atapi_cmd_reply_end() function in hw/ide/atapi.c in QEMU. A remote user can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.


Affected software

QEMU
Red Hat Virtualization Manager
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
CentOS
openEuler
qemu-kvm (Red Hat package)
qemu-kvm-rhev (Red Hat package)
qemu
qemu-img
qemu-debuginfo
qemu-guest-agent
qemu-debugsource
qemu-help
qemu-seabios

How to mitigate CVE-2020-29443

Install updates from vendor's website.

QEMU - update to 5.2.0
qemu-kvm (Red Hat package) - update to 1.5.3-175.el7_9.4
qemu-kvm-rhev (Red Hat package) - update to 2.12.0-48.el7_9.3
qemu - update to 4.1.0-35
qemu-img - update to 4.1.0-35
qemu-debuginfo - update to 4.1.0-35
qemu-guest-agent - update to 4.1.0-35
qemu-debugsource - update to 4.1.0-35
qemu-help - update to 4.1.0-35
qemu-seabios - update to 4.1.0-35

External References

Related Security Bulletins