CVE-2016-4020
published 2016-05-25CVE-2016-4020: The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain…
PriorityP425medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.37%
29.8th percentile
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.6+dfsg-2 (bookworm) | qemu 1:2.6+dfsg-2 (bookworm) |
| qemu | qemu | <= 2.6.2 | — |
| qemu | qemu | >= 0 < 1:2.6+dfsg-2 | 1:2.6+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.6+dfsg-2 | 1:2.6+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.6+dfsg-2 | 1:2.6+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.6+dfsg-2 | 1:2.6+dfsg-2 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.24 | 2.0.0+dfsg-2ubuntu1.24 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.1 | 1:2.5+dfsg-5ubuntu10.1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2016-05-12·CVSS 5.0
CVE-2016-2391 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Zuozhi Fzz discovered that QEMU incorrectly handled USB OHCI emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2391)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2392)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly leak
host memory bytes. (CVE-2016-2538)
Hongke Yang discovered that QEMU i
Red Hat
Qemu: i386: leakage of stack memory to guest in kvmvapic.c
vendor_redhat·2016-04-07·CVSS 6.5
CVE-2016-4020 [MEDIUM] CWE-200 Qemu: i386: leakage of stack memory to guest in kvmvapic.c
Qemu: i386: leakage of stack memory to guest in kvmvapic.c
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
An information-exposure flaw was found in Quick Emulator (QEMU) in Task Priority Register (TPR) optimizations for 32-bit Windows guests. The flaw could occur while accessing TPR. A privileged user inside a guest could use this issue to read portions of the host memory.
Statement: This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle:
https://access
Debian
CVE-2016-4020: qemu - The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize...
vendor_debian·2016·CVSS 6.5
CVE-2016-4020 [MEDIUM] CVE-2016-4020: qemu - The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize...
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-2)
bullseye: resolved (fixed in 1:2.6+dfsg-2)
forky: resolved (fixed in 1:2.6+dfsg-2)
sid: resolved (fixed in 1:2.6+dfsg-2)
trixie: resolved (fixed in 1:2.6+dfsg-2)
GHSA
GHSA-vcqr-cc8h-57gj: The patch_instruction function in hw/i386/kvmvapic
ghsa_unreviewed·2022-05-13
CVE-2016-4020 [MEDIUM] GHSA-vcqr-cc8h-57gj: The patch_instruction function in hw/i386/kvmvapic
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
OSV
CVE-2016-4020: The patch_instruction function in hw/i386/kvmvapic
osv·2016-05-25·CVSS 6.5
CVE-2016-4020 [MEDIUM] CVE-2016-4020: The patch_instruction function in hw/i386/kvmvapic
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
OSV
qemu, qemu-kvm vulnerabilities
osv·2016-05-12·CVSS 5.0
CVE-2016-2391 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Zuozhi Fzz discovered that QEMU incorrectly handled USB OHCI emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2391)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2016-2392)
Qinghao Tang discovered that QEMU incorrectly handled USB Net emulation
support. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service, or possibly leak
host memory bytes. (CVE-2016-2538)
Hongke Yang discovered that QEMU incorrectly handled NE2000 emulation
support. A priv
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4020 qemu: qemu-kvm: Leakage of stack memory to guest in kvmvapic.c [fedora-all]
bugzilla·2016-04-13·CVSS 6.5
CVE-2016-4020 [MEDIUM] CVE-2016-4020 qemu: qemu-kvm: Leakage of stack memory to guest in kvmvapic.c [fedora-all]
CVE-2016-4020 qemu: qemu-kvm: Leakage of stack memory to guest in kvmvapic.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2016-4020 Qemu: i386: leakage of stack memory to guest in kvmvapic.c
bugzilla·2016-03-02·CVSS 6.5
CVE-2016-4020 [MEDIUM] CVE-2016-4020 Qemu: i386: leakage of stack memory to guest in kvmvapic.c
CVE-2016-4020 Qemu: i386: leakage of stack memory to guest in kvmvapic.c
Qemu emulator built with the Task Priority Register(TPR) optimizations for 32-bit Windows guests, is vulnerable to a information leakage issue. It could
occur while accessing Task Priority Register(TPR).
A privileged user/process inside guest could use this issue to leak host memory bytes.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01118.html
Reference:
-> http://www.openwall.com/lists/oss-security/2016/04/14/3
Discussion:
Acknowledgments:
Name: Donghai Zdh (Alibaba Inc.)
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1326904]
---
qemu-2.6.0-3.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=691a02e2ce0c413236a78dee6f2651c937b09fb0http://www.securityfocus.com/bid/86067http://www.ubuntu.com/usn/USN-2974-1https://access.redhat.com/errata/RHSA-2017:1856https://access.redhat.com/errata/RHSA-2017:2392https://access.redhat.com/errata/RHSA-2017:2408https://bugzilla.redhat.com/show_bug.cgi?id=1313686https://lists.debian.org/debian-lts-announce/2018/11/msg00038.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01106.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01118.htmlhttps://security.gentoo.org/glsa/201609-01http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=691a02e2ce0c413236a78dee6f2651c937b09fb0http://www.securityfocus.com/bid/86067http://www.ubuntu.com/usn/USN-2974-1https://access.redhat.com/errata/RHSA-2017:1856https://access.redhat.com/errata/RHSA-2017:2392https://access.redhat.com/errata/RHSA-2017:2408https://bugzilla.redhat.com/show_bug.cgi?id=1313686https://lists.debian.org/debian-lts-announce/2018/11/msg00038.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01106.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01118.htmlhttps://security.gentoo.org/glsa/201609-01
2016-05-25
Published