CVE-2020-11102
published 2020-04-06CVE-2020-11102: hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
PriorityP430medium5.6CVSS 3.1
AVNACHPRNUINSUCLILAL
EPSS
1.92%
77.8th percentile
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:4.2-4 (bookworm) | qemu 1:4.2-4 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_qemu-kvm_4.2.0-13_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:4.2-4 | 1:4.2-4 |
| qemu | qemu | >= 0 < 1:4.2-4 | 1:4.2-4 |
| qemu | qemu | >= 0 < 1:4.2-4 | 1:4.2-4 |
| qemu | qemu | >= 0 < 1:4.2-4 | 1:4.2-4 |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_msrc5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
vendor_msrc·2020-04-14·CVSS 5.6
CVE-2020-11102 [MEDIUM] CWE-787 hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitr
Red Hat
QEMU: tulip: OOB access in tulip_copy_tx_buffers
vendor_redhat·2020-02-11·CVSS 5.6
CVE-2020-11102 [MEDIUM] CWE-125 QEMU: tulip: OOB access in tulip_copy_tx_buffers
QEMU: tulip: OOB access in tulip_copy_tx_buffers
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
An out-of-bounds access flaw was found in the Tulip NIC emulator built into QEMU. This flaw occurs while copying network data to and from its tx/rx frame buffers, as it does not check frame size against the data length. This flaw allows a remote user or process to crash the QEMU process, resulting in a denial of service or the potential execution of arbitrary code with the privileges of the QEMU process on the host.
Statement: This issue does not affect the versions of the qemu-kvm package as shipped with Red Hat Enterprise Linux 6, 7 and 8.
Package: kvm (Red Hat Enterprise Linux 5) -
Debian
CVE-2020-11102: qemu - hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx b...
vendor_debian·2020·CVSS 5.6
CVE-2020-11102 [MEDIUM] CVE-2020-11102: qemu - hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx b...
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
Scope: local
bookworm: resolved (fixed in 1:4.2-4)
bullseye: resolved (fixed in 1:4.2-4)
forky: resolved (fixed in 1:4.2-4)
sid: resolved (fixed in 1:4.2-4)
trixie: resolved (fixed in 1:4.2-4)
GHSA
GHSA-c632-pw4c-82pg: hw/net/tulip
ghsa_unreviewed·2022-05-24
CVE-2020-11102 [HIGH] GHSA-c632-pw4c-82pg: hw/net/tulip
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
OSV
CVE-2020-11102: hw/net/tulip
osv·2020-04-06·CVSS 5.6
CVE-2020-11102 [MEDIUM] CVE-2020-11102: hw/net/tulip
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-11102 qemu: tulip: OOB access in tulip_copy_tx_buffers [fedora-rawhide]
bugzilla·2020-04-07·CVSS 5.6
CVE-2020-11102 [MEDIUM] CVE-2020-11102 qemu: tulip: OOB access in tulip_copy_tx_buffers [fedora-rawhide]
CVE-2020-11102 qemu: tulip: OOB access in tulip_copy_tx_buffers [fedora-rawhide]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-rawhide.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to fo
Bugzilla
CVE-2020-11102 QEMU: tulip: OOB access in tulip_copy_tx_buffers
bugzilla·2020-04-06·CVSS 5.6
CVE-2020-11102 [MEDIUM] CVE-2020-11102 QEMU: tulip: OOB access in tulip_copy_tx_buffers
CVE-2020-11102 QEMU: tulip: OOB access in tulip_copy_tx_buffers
An out-of-bounds access issue was found in the Tulip NIC emulator built into QEMU.
It could occur while copying network data to/from its tx/rx frame buffers, as it
does not check frame size against the data length.
A remote user/process could use this flaw to crash the QEMU process resulting in Dos
OR potentially execute arbitrary code with the privileges of the QEMU process on the host.
Upstream patch:
-> https://git.qemu.org/?p=qemu.git;a=commit;h=8ffb7265af64ec81748335ec8f20e7ab542c3850
Reference:
-> https://www.openwall.com/lists/oss-security/2020/04/06/1
Discussion:
Acknowledgments:
Name: Ziming Zhang, Li Qiang (Tianchen Security Lab of Ant Financial)
---
Statement:
This issue does not affect the versions of the
http://www.openwall.com/lists/oss-security/2020/04/06/1http://www.openwall.com/lists/oss-security/2020/04/06/1https://lists.gnu.org/archive/html/qemu-devel/2020-03/msg08322.htmlhttps://security.gentoo.org/glsa/202005-02http://www.openwall.com/lists/oss-security/2020/04/06/1http://www.openwall.com/lists/oss-security/2020/04/06/1https://lists.gnu.org/archive/html/qemu-devel/2020-03/msg08322.htmlhttps://security.gentoo.org/glsa/202005-02
2020-04-06
Published