CVE-2019-20382
published 2020-03-05CVE-2019-20382: QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation…
PriorityP410low3.5CVSS 3.1
AVAACLPRLUINSUCNINAL
EPSS
0.87%
54.4th percentile
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:4.2-1 (bookworm) | qemu 1:4.2-1 (bookworm) |
| opensuse | leap | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.44 | 1:2.5+dfsg-5ubuntu10.44 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.26 | 1:2.11+dfsg-1ubuntu7.26 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.30 | 1:4.2-3ubuntu6.30 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.1 | 1:4.2-3ubuntu6.1 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.24 | 1:6.2+dfsg-2ubuntu6.24 |
| qemu | qemu | >= 0 < 1:8.2.2+ds-0ubuntu1.4 | 1:8.2.2+ds-0ubuntu1.4 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.47+esm4 | 2.0.0+dfsg-2ubuntu1.47+esm4 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.51+esm3 | 1:2.5+dfsg-5ubuntu10.51+esm3 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.42+esm2 | 1:2.11+dfsg-1ubuntu7.42+esm2 |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
osv5.8MEDIUM
vendor_ubuntu5.8MEDIUM
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
qemu vulnerabilities
osv·2024-11-08·CVSS 3.5
CVE-2019-20382 [LOW] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2019-20382)
It was discovered that QEMU incorrectly handled certain memory copy
operations when loading ROM contents. If a user were tricked into running
an untrusted kernel image, a remote attacker could possibly use this issue
to run arbitrary code. This issue only affected Ubuntu 14.04 LTS.
(CVE-2020-13765)
Aviv Sasson discovered that QEMU incorrectly handled Slirp networking. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
denial of service, or possibly execute arbitrary code. This iss
GHSA
GHSA-gg7h-8w45-pgpg: QEMU 4
ghsa_unreviewed·2022-05-24
CVE-2019-20382 [MEDIUM] CWE-401 GHSA-gg7h-8w45-pgpg: QEMU 4
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
OSV
qemu vulnerabilities
osv·2020-05-21·CVSS 5.8
CVE-2019-15034 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled bochs-display devices. A
local attacker in a guest could use this to cause a denial of service or
possibly execute arbitrary code in the host. This issue only affected
Ubuntu 19.10. (CVE-2019-15034)
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10.
(CVE-2019-20382)
It was discovered that QEMU incorrectly generated QEMU Pointer
Authentication signatures on ARM. A local attacker could possibly use this
issue to bypass PAuth. This issue only affected Ubuntu 19.10.
(CVE-2020-10702)
Ziming Zhan
OSV
CVE-2019-20382: QEMU 4
osv·2020-03-05·CVSS 3.5
CVE-2019-20382 [LOW] CVE-2019-20382: QEMU 4
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2024-11-08·CVSS 3.5
CVE-2020-8608 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2019-20382)
It was discovered that QEMU incorrectly handled certain memory copy
operations when loading ROM contents. If a user were tricked into running
an untrusted kernel image, a remote attacker could possibly use this issue
to run arbitrary code. This issue only affected Ubuntu 14.04 LTS.
(CVE-2020-13765)
Aviv Sasson discovered that QEMU incorrectly handled Slirp networking. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
de
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2020-05-21·CVSS 5.8
CVE-2019-15034 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled bochs-display devices. A
local attacker in a guest could use this to cause a denial of service or
possibly execute arbitrary code in the host. This issue only affected
Ubuntu 19.10. (CVE-2019-15034)
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10.
(CVE-2019-20382)
It was discovered that QEMU incorrectly generated QEMU Pointer
Authentication signatures on ARM. A local attacker could possibly use this
issue to bypass PAuth. This is
Red Hat
QEMU: vnc: memory leakage upon disconnect
vendor_redhat·2019-09-17·CVSS 3.5
CVE-2019-20382 [LOW] CWE-401 QEMU: vnc: memory leakage upon disconnect
QEMU: vnc: memory leakage upon disconnect
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
A memory leakage flaw was found in the way the VNC display driver of QEMU handled the connection disconnect when ZRLE and Tight encoding are enabled. Two VncState objects are created, and one allocates memory for the Zlib's data object. This allocated memory is not freed upon disconnection, resulting in a memory leak. An attacker able to connect to the VNC server could use this flaw to leak host memory, leading to a potential denial of service.
Statement: This flaw did not affect the versions of `qemu-kvm` as shipped with Red
Debian
CVE-2019-20382: qemu - QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a...
vendor_debian·2019·CVSS 3.5
CVE-2019-20382 [LOW] CVE-2019-20382: qemu - QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a...
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
Scope: local
bookworm: resolved (fixed in 1:4.2-1)
bullseye: resolved (fixed in 1:4.2-1)
forky: resolved (fixed in 1:4.2-1)
sid: resolved (fixed in 1:4.2-1)
trixie: resolved (fixed in 1:4.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20382 QEMU: vnc: memory leakage upon disconnect
bugzilla·2020-03-05·CVSS 3.5
CVE-2019-20382 [LOW] CVE-2019-20382 QEMU: vnc: memory leakage upon disconnect
CVE-2019-20382 QEMU: vnc: memory leakage upon disconnect
A memory leakage flaw was found in the way VNC display driver of QEMU handled connection disconnect, when ZRLE, Tight encoding is enabled. It creates two vncState objects, one of which allocates memory for Zlib's data object. This allocated memory is not free'd upon disconnection resulting in the said memory leakage issue. A user able to connect to the VNC server could use this flaw to leak host memory leading to a potential DoS scenario.
Upstream patch:
-> https://git.qemu.org/?p=qemu.git;a=commitdiff;h=6bf21f3d83e95bcc4ba35a7a07cc6655e8b010b0
Discussion:
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1810391]
---
Statement:
This flaw did not affect the versions of `qemu-kvm` as shipped with Red Hat Ente
Bugzilla
CVE-2019-20382 qemu: vnc: memory leakage upon disconnect [fedora-all]
bugzilla·2020-03-05·CVSS 3.5
CVE-2019-20382 [LOW] CVE-2019-20382 qemu: vnc: memory leakage upon disconnect [fedora-all]
CVE-2019-20382 qemu: vnc: memory leakage upon disconnect [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2019-20382 virt:8.1/qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-av-8]
bugzilla·2020-01-07·CVSS 3.5
CVE-2019-20382 [LOW] CVE-2019-20382 virt:8.1/qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-av-8]
CVE-2019-20382 virt:8.1/qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-av-8]
Created attachment 1650300
valgrind log
Description of problem:
As subject
Version-Release number of selected component (if applicable):
qemu-kvm-4.1.0-20.module+el8.1.1+5309+6d656f05.x86_64
How reproducible:
100%
Steps to Reproduce:
1. Start a qemu with vnc together with valgrind
# valgrind --log-file=vnc-memleak.log --leak-check=full /usr/libexec/qemu-kvm -vnc 0.0.0.0:0
2. Use remote-viewer to connect vnc for some times
# for i in {1..10};do timeout -s INT 2 remote-viewer vnc://[HOST_IP]:5900;done
You can also start qemu directly and connect vnc for some times. Check the rss useage increasing on qemu process.
3. Memleak log:
==24942== 131,072 bytes in 1 blocks are possibly lost in loss record
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.htmlhttp://www.openwall.com/lists/oss-security/2020/03/05/1https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=6bf21f3d83e95bcc4ba35a7a07cc6655e8b010b0https://lists.debian.org/debian-lts-announce/2020/07/msg00020.htmlhttps://usn.ubuntu.com/4372-1/https://www.debian.org/security/2020/dsa-4665http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.htmlhttp://www.openwall.com/lists/oss-security/2020/03/05/1https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=6bf21f3d83e95bcc4ba35a7a07cc6655e8b010b0https://lists.debian.org/debian-lts-announce/2020/07/msg00020.htmlhttps://usn.ubuntu.com/4372-1/https://www.debian.org/security/2020/dsa-4665
2020-03-05
Published