cbcvebase.
CVE-2020-10702
published 2020-06-04

CVE-2020-10702: A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.33%
25.6th percentile
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:4.2-5 (bookworm)qemu 1:4.2-5 (bookworm)
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_qemu-kvm_4.2.0-21_on_cbl_mariner_1.0
qemuqemu>= 0 < 1:4.2-51:4.2-5
qemuqemu>= 0 < 1:4.2-51:4.2-5
qemuqemu>= 0 < 1:4.2-51:4.2-5
qemuqemu>= 0 < 1:4.2-51:4.2-5
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.441:2.5+dfsg-5ubuntu10.44
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.261:2.11+dfsg-1ubuntu7.26
qemuqemu>= 0 < 1:4.2-3ubuntu6.11:4.2-3ubuntu6.1
qemuqemu>= 4.0.0 < 5.0.05.0.0
the_qemu_projectqemu

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.8MEDIUM
vendor_ubuntu5.8MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.