CVE-2020-13361Out-of-bounds Write in Qemu

CWE-787Out-of-bounds Write14 documents9 sources
Severity
3.9LOWNVD
OSV6.5OSV5.5
EPSS
0.1%
top 73.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 28
Latest updateMay 24

Description

In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:LExploitability: 0.8 | Impact: 2.7

Affected Packages4 packages

Debianqemu/qemu< 1:5.0-6+3
Ubuntuqemu/qemu< 1:2.5+dfsg-5ubuntu10.45+3
NVDqemu/qemu5.0.0
NVDopensuse/leap15.2

Also affects: Debian Linux 10.0, 8.0, 9.0, Ubuntu Linux 16.04, 18.04, 20.04

Patches

🔴Vulnerability Details

5
GHSA
GHSA-48jr-qqfg-77f3: In QEMU 42022-05-24
OSV
qemu vulnerabilities2021-02-02
OSV
qemu vulnerabilities2020-08-19
OSV
CVE-2020-13361: In QEMU 52020-05-28
CVEList
CVE-2020-13361: In QEMU 52020-05-28

📋Vendor Advisories

5
Ubuntu
QEMU vulnerabilities2021-02-02
Ubuntu
QEMU vulnerabilities2020-08-19
Red Hat
QEMU: es1370: OOB access due to incorrect frame count leads to DoS2020-05-15
Microsoft
In QEMU 5.0.0 and earlier es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count which allows guest OS users to trigger an out-of-bounds access during an es1370_write() 2020-05-12
Debian
CVE-2020-13361: qemu - In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not p...2020

💬Community

3
Bugzilla
CVE-2020-13361 QEMU: es1370: OOB access due to incorrect frame count leads to DoS2020-05-28
Bugzilla
CVE-2020-13361 xen: QEMU: es1370: OOB access due to incorrect frame count leads to DoS [fedora-all]2020-05-28
Bugzilla
CVE-2020-13361 qemu: es1370: OOB access due to incorrect frame count leads to DoS [fedora-all]2020-05-28
CVE-2020-13361 — Out-of-bounds Write in Qemu | cvebase