Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13659

Опубликовано: 14 мая 2020
Источник: redhat
CVSS3: 2.5

Описание

address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.

A NULL pointer dereference flaw was found in the MegaRAID SAS 8708EM2 emulator of the QEMU. This issue occurs because the address_space_map() API while mapping physical memory into the host's virtual address space, may return NULL without setting the length parameter to zero (0). This flaw allows a guest user or process to crash the QEMU process on the host resulting in a denial of service.

Отчет

In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP qemu-kvm-rhev package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maFix deferred
Red Hat Enterprise Linux 7qemu-kvm-rhevFix deferred
Red Hat Enterprise Linux 8virt:rhel/qemu-kvmFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmFix deferred
Red Hat Enterprise Linux 9qemu-kvmNot affected
Red Hat OpenStack Platform 10 (Newton)qemu-kvm-rhevWill not fix
Red Hat OpenStack Platform 13 (Queens)qemu-kvm-rhevWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1842496QEMU: exec: address_space_map returns NULL without setting length to zero may lead to DoS

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
около 5 лет назад

address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.

CVSS3: 2.5
nvd
около 5 лет назад

address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.

CVSS3: 2.5
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 2.5
debian
около 5 лет назад

address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer d ...

CVSS3: 2.5
github
около 3 лет назад

address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.

2.5 Low

CVSS3