Описание
The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 1:2.10+dfsg-0ubuntu3.6 |
| bionic | released | 1:2.11+dfsg-1ubuntu7.1 |
| cosmic | released | 1:2.11+dfsg-1ubuntu9 |
| devel | released | 1:2.11+dfsg-1ubuntu9 |
| disco | released | 1:2.11+dfsg-1ubuntu9 |
| eoan | released | 1:2.11+dfsg-1ubuntu9 |
| esm-infra-legacy/trusty | released | 2.0.0+dfsg-2ubuntu1.41 |
| esm-infra/bionic | released | 1:2.11+dfsg-1ubuntu7.1 |
| esm-infra/focal | released | 1:2.11+dfsg-1ubuntu9 |
| esm-infra/xenial | released | 1:2.5+dfsg-5ubuntu10.28 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | DNE | |
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| disco | DNE | |
| eoan | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE |
Показывать по
EPSS
4.6 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.
The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.
The load_multiboot function in hw/i386/multiboot.c in Quick Emulator ( ...
The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.
Уязвимость функции load_multiboot эмулятора аппаратного обеспечения Qemu, связанная с записью за границами буфера памяти, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
EPSS
4.6 Medium
CVSS2
8.8 High
CVSS3