Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13362

Опубликовано: 07 мая 2020
Источник: redhat
CVSS3: 3.2

Описание

In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.

An out-of bounds read-access flaw was found in the MegaRAID SAS 8708EM2 emulator of the QEMU. This flaw occurs in the' megasas_lookup_frame' routine when the 's->reply_queue_head' is set to a malicious value. A guest user or process may use this flaw to crash the QEMU process on the host resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 7qemu-kvm-rhevNot affected
Red Hat Enterprise Linux 8virt:rhel/qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmNot affected
Red Hat Enterprise Linux 9qemu-kvmNot affected
Red Hat OpenStack Platform 10 (Newton)qemu-kvm-rhevNot affected
Red Hat OpenStack Platform 13 (Queens)qemu-kvm-rhevNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1840999QEMU: megasas: OOB read access due to invalid index leads to DoS

3.2 Low

CVSS3

Связанные уязвимости

CVSS3: 3.2
ubuntu
около 5 лет назад

In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.

CVSS3: 3.2
nvd
около 5 лет назад

In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.

CVSS3: 3.2
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 3.2
debian
около 5 лет назад

In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c h ...

CVSS3: 3.2
github
около 3 лет назад

In QEMU 4.2.0, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.

3.2 Low

CVSS3