ISOMAN

CVE

CVE-2020-13765

rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.

Severity
MEDIUM
CVSS
5.6
Published
Modified

Linked Releases

References

  1. https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=e423455c4f23a1a828901c78fe6d03b7dde79319
  2. https://github.com/qemu/qemu/commit/4f1c6cb2f9afafda05eab150fd2bd284edce6676
  3. https://lists.debian.org/debian-lts-announce/2020/06/msg00032.html
  4. https://lists.debian.org/debian-lts-announce/2020/07/msg00020.html
  5. https://security.netapp.com/advisory/ntap-20200619-0006/
  6. https://usn.ubuntu.com/4467-1/
  7. https://www.openwall.com/lists/oss-security/2020/06/03/6
  8. https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=e423455c4f23a1a828901c78fe6d03b7dde79319
  9. https://github.com/qemu/qemu/commit/4f1c6cb2f9afafda05eab150fd2bd284edce6676
  10. https://lists.debian.org/debian-lts-announce/2020/06/msg00032.html
  11. https://lists.debian.org/debian-lts-announce/2020/07/msg00020.html
  12. https://security.netapp.com/advisory/ntap-20200619-0006/
  13. https://usn.ubuntu.com/4467-1/
  14. https://www.openwall.com/lists/oss-security/2020/06/03/6