CVE-2020-10702Missing Cryptographic Step in Qemu

Severity
5.5MEDIUMNVD
OSV5.8
EPSS
0.0%
top 89.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 4
Latest updateMay 24

Description

A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages8 packages

NVDqemu/qemu4.0.05.0.0
debiandebian/qemu< qemu 1:4.2-5 (bookworm)
Debianqemu/qemu< 1:4.2-5+3
Ubuntuqemu/qemu< 1:2.5+dfsg-5ubuntu10.44+2
CVEListV5the_qemu_project/qemu>= 4.0.0, < 5.0.0

🔴Vulnerability Details

3
GHSA
GHSA-g793-9qm5-f3q5: A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 42022-05-24
OSV
CVE-2020-10702: A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 42020-06-04
OSV
qemu vulnerabilities2020-05-21

📋Vendor Advisories

4
Microsoft
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation2020-06-09
Ubuntu
QEMU vulnerabilities2020-05-21
Red Hat
qemu: weak signature generation in Pointer Authentication support for ARM2020-04-02
Debian
CVE-2020-10702: qemu - A flaw was found in QEMU in the implementation of the Pointer Authentication (PA...2020

💬Community

2
Bugzilla
CVE-2020-10702 qemu: weak signature generation in Pointer Authentication support for ARM [fedora-all]2020-04-02
Bugzilla
CVE-2020-10702 qemu: weak signature generation in Pointer Authentication support for ARM2020-03-04