CVE-2020-13754 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Qemu
Severity
6.7MEDIUMNVD
OSV6.5OSV5.5
EPSS
0.0%
top 91.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 2
Latest updateMay 24
Description
hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9
Patches
🔴Vulnerability Details
6📋Vendor Advisories
6Microsoft▶
hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.↗2020-06-09