CVE-2019-20808
published 2020-12-31CVE-2019-20808: In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write…
PriorityP424medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.33%
25.4th percentile
In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:4.2-1 (bookworm) | qemu 1:4.2-1 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
QEMU: out-of-bounds read in ati_cursor_define() function in hw/display/ati.c leads to DoS
vendor_redhat·2019-09-13·CVSS 6.5
CVE-2019-20808 [MEDIUM] CWE-125 QEMU: out-of-bounds read in ati_cursor_define() function in hw/display/ati.c leads to DoS
QEMU: out-of-bounds read in ati_cursor_define() function in hw/display/ati.c leads to DoS
In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
An out-of-bounds read flaw was found in the ATI VGA implementation of the QEMU emulator. This flaw occurs in the ati_cursor_define() routine while handling MMIO write operations through ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
Statement: This flaw did not affect the following versions of QEMU as they did not include s
Debian
CVE-2019-20808: qemu - In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementatio...
vendor_debian·2019·CVSS 6.5
CVE-2019-20808 [MEDIUM] CVE-2019-20808: qemu - In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementatio...
In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 1:4.2-1)
bullseye: resolved (fixed in 1:4.2-1)
forky: resolved (fixed in 1:4.2-1)
sid: resolved (fixed in 1:4.2-1)
trixie: resolved (fixed in 1:4.2-1)
GHSA
GHSA-p8fx-hg9x-79mx: In QEMU 4
ghsa_unreviewed·2022-05-24
CVE-2019-20808 [MEDIUM] CWE-125 GHSA-p8fx-hg9x-79mx: In QEMU 4
In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
OSV
CVE-2019-20808: In QEMU 4
osv·2020-12-31·CVSS 6.5
CVE-2019-20808 [MEDIUM] CVE-2019-20808: In QEMU 4
In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20808 QEMU: out-of-bounds read in ati_cursor_define() function in hw/display/ati.c leads to DoS
bugzilla·2020-05-28·CVSS 6.5
CVE-2019-20808 [MEDIUM] CVE-2019-20808 QEMU: out-of-bounds read in ati_cursor_define() function in hw/display/ati.c leads to DoS
CVE-2019-20808 QEMU: out-of-bounds read in ati_cursor_define() function in hw/display/ati.c leads to DoS
An out-of-bounds read flaw was found in function ati_cursor_define() in hw/display/ati.c, leading to possible denial of service under certain conditions.
Upstream fix:
https://git.qemu.org/?p=qemu.git;a=commit;h=aab0e2a661b2b6bf7915c0aefe807fb60d6d9d13
Discussion:
Statement:
This flaw did not affect the following versions of QEMU as they did not include support for ATI VGA emulation:
* `qemu-kvm-ma` as shipped with Red Hat Enterprise Linux 7.
* `qemu-kvm-rhev` as shipped with Red Hat Virtualization and Red Hat OpenStack.
* `qemu-kvm` as shipped with Red Hat Enterprise Linux 6, 7 and 8.
* `virt:8.2/qemu-kvm` as shipped with RHEL Advanced Virtualization.
ATI VGA emulation feature wa
Bugzilla
CVE-2019-20808 qemu: out-of-bounds read in ati_cursor_define() function in hw/display/ati.c leads to DoS [fedora-all]
bugzilla·2020-05-28·CVSS 6.5
CVE-2019-20808 [MEDIUM] CVE-2019-20808 qemu: out-of-bounds read in ati_cursor_define() function in hw/display/ati.c leads to DoS [fedora-all]
CVE-2019-20808 qemu: out-of-bounds read in ati_cursor_define() function in hw/display/ati.c leads to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
https://bugzilla.redhat.com/show_bug.cgi?id=1841136https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=aab0e2a661b2b6bf7915c0aefe807fb60d6d9d13https://security.netapp.com/advisory/ntap-20210205-0003/https://bugzilla.redhat.com/show_bug.cgi?id=1841136https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=aab0e2a661b2b6bf7915c0aefe807fb60d6d9d13https://security.netapp.com/advisory/ntap-20210205-0003/
2020-12-31
Published