Out-of-bounds read in QEMU - CVE-2020-29443
Published: January 26, 2021 / Updated: January 26, 2021
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the ide_atapi_cmd_reply_end() function in hw/ide/atapi.c in QEMU. A remote user can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Red Hat Virtualization Manager
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
CentOS
openEuler
qemu-kvm (Red Hat package)
qemu-kvm-rhev (Red Hat package)
qemu
qemu-img
qemu-debuginfo
qemu-guest-agent
qemu-debugsource
qemu-help
qemu-seabios
How to mitigate CVE-2020-29443
qemu-kvm (Red Hat package) - update to 1.5.3-175.el7_9.4
qemu-kvm-rhev (Red Hat package) - update to 2.12.0-48.el7_9.3
qemu - update to 4.1.0-35
qemu-img - update to 4.1.0-35
qemu-debuginfo - update to 4.1.0-35
qemu-guest-agent - update to 4.1.0-35
qemu-debugsource - update to 4.1.0-35
qemu-help - update to 4.1.0-35
qemu-seabios - update to 4.1.0-35