Описание
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 1:2.11+dfsg-1ubuntu7.40 |
devel | released | 1:6.2+dfsg-2ubuntu8 |
esm-infra-legacy/trusty | needs-triage | |
esm-infra/bionic | not-affected | 1:2.11+dfsg-1ubuntu7.40 |
esm-infra/focal | not-affected | 1:4.2-3ubuntu6.23 |
esm-infra/xenial | needs-triage | |
focal | released | 1:4.2-3ubuntu6.23 |
impish | released | 1:6.0+dfsg-2expubuntu1.3 |
jammy | released | 1:6.2+dfsg-2ubuntu6.2 |
kinetic | released | 1:6.2+dfsg-2ubuntu8 |
Показывать по
4.6 Medium
CVSS2
8.2 High
CVSS3
Связанные уязвимости
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
A flaw was found in the QXL display device emulation in QEMU. An integ ...
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
4.6 Medium
CVSS2
8.2 High
CVSS3