CVE-2020-10702
published 2020-06-04CVE-2020-10702: A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.33%
25.6th percentile
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:4.2-5 (bookworm) | qemu 1:4.2-5 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_qemu-kvm_4.2.0-21_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | >= 0 < 1:4.2-5 | 1:4.2-5 |
| qemu | qemu | >= 0 < 1:4.2-5 | 1:4.2-5 |
| qemu | qemu | >= 0 < 1:4.2-5 | 1:4.2-5 |
| qemu | qemu | >= 0 < 1:4.2-5 | 1:4.2-5 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.44 | 1:2.5+dfsg-5ubuntu10.44 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.26 | 1:2.11+dfsg-1ubuntu7.26 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.1 | 1:4.2-3ubuntu6.1 |
| qemu | qemu | >= 4.0.0 < 5.0.0 | 5.0.0 |
| the_qemu_project | qemu | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.8MEDIUM
vendor_ubuntu5.8MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g793-9qm5-f3q5: A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4
ghsa_unreviewed·2022-05-24
CVE-2020-10702 [LOW] GHSA-g793-9qm5-f3q5: A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.
OSV
CVE-2020-10702: A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4
osv·2020-06-04·CVSS 5.5
CVE-2020-10702 [MEDIUM] CVE-2020-10702: A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.
OSV
qemu vulnerabilities
osv·2020-05-21·CVSS 5.8
CVE-2019-15034 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled bochs-display devices. A
local attacker in a guest could use this to cause a denial of service or
possibly execute arbitrary code in the host. This issue only affected
Ubuntu 19.10. (CVE-2019-15034)
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10.
(CVE-2019-20382)
It was discovered that QEMU incorrectly generated QEMU Pointer
Authentication signatures on ARM. A local attacker could possibly use this
issue to bypass PAuth. This issue only affected Ubuntu 19.10.
(CVE-2020-10702)
Ziming Zhan
Microsoft
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation
vendor_msrc·2020-06-09·CVSS 5.5
CVE-2020-10702 [MEDIUM] CWE-325 A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro i
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2020-05-21·CVSS 5.8
CVE-2019-15034 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled bochs-display devices. A
local attacker in a guest could use this to cause a denial of service or
possibly execute arbitrary code in the host. This issue only affected
Ubuntu 19.10. (CVE-2019-15034)
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10.
(CVE-2019-20382)
It was discovered that QEMU incorrectly generated QEMU Pointer
Authentication signatures on ARM. A local attacker could possibly use this
issue to bypass PAuth. This is
Red Hat
qemu: weak signature generation in Pointer Authentication support for ARM
vendor_redhat·2020-04-02·CVSS 5.5
CVE-2020-10702 [MEDIUM] CWE-325 qemu: weak signature generation in Pointer Authentication support for ARM
qemu: weak signature generation in Pointer Authentication support for ARM
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected poin
Debian
CVE-2020-10702: qemu - A flaw was found in QEMU in the implementation of the Pointer Authentication (PA...
vendor_debian·2020·CVSS 5.5
CVE-2020-10702 [MEDIUM] CVE-2020-10702: qemu - A flaw was found in QEMU in the implementation of the Pointer Authentication (PA...
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.
Scope: local
bookworm: resolved (fixed in 1:4.2-5)
bullseye: resolved (fixed in 1:4.2-5)
forky: resolved (fixed in 1:4.2-5)
sid: resolved (fixed in 1:4.2-5)
trixie: resolved (fixed in 1:4.2-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10702 qemu: weak signature generation in Pointer Authentication support for ARM [fedora-all]
bugzilla·2020-04-02·CVSS 5.5
CVE-2020-10702 [MEDIUM] CVE-2020-10702 qemu: weak signature generation in Pointer Authentication support for ARM [fedora-all]
CVE-2020-10702 qemu: weak signature generation in Pointer Authentication support for ARM [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2020-10702 qemu: weak signature generation in Pointer Authentication support for ARM
bugzilla·2020-03-04·CVSS 5.5
CVE-2020-10702 [MEDIUM] CVE-2020-10702 qemu: weak signature generation in Pointer Authentication support for ARM
CVE-2020-10702 qemu: weak signature generation in Pointer Authentication support for ARM
A flaw was found in QEMU Pointer Authentication (PAuth) support for ARM introduced in version 4.0.
Specifically, a general failure of the signature generation process causes every PAuth-enforced pointer to be signed with the same signature, resulting in weaker encryption than advertised by the design of the PAuth technique.
An attacker can easily obtain the signature of the protected pointer, and bypass PAuth through brute force guessing or information disclosure vulnerabilities, and all programs running on QEMU will lose protection from PAuth.
Discussion:
(In reply to Mauro Matteo Cascella from comment #1)
> Statement:
>
> This flaw did not affect the versions of `qemu-kvm-ma` as shipped with Red
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10702https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=de0b1bae6461f67243282555475f88b2384a1eb9https://security.netapp.com/advisory/ntap-20200724-0007/https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10702https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=de0b1bae6461f67243282555475f88b2384a1eb9https://security.netapp.com/advisory/ntap-20200724-0007/
2020-06-04
Published