CVE-2020-13765
published 2020-06-04CVE-2020-13765: rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid…
PriorityP429medium5.6CVSS 3.1
AVNACHPRNUINSUCLILAL
EPSS
2.41%
82.4th percentile
rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:4.2-1 (bookworm) | qemu 1:4.2-1 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:4.2-1 | 1:4.2-1 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.45 | 1:2.5+dfsg-5ubuntu10.45 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.31 | 1:2.11+dfsg-1ubuntu7.31 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.30 | 1:4.2-3ubuntu6.30 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.4 | 1:4.2-3ubuntu6.4 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.24 | 1:6.2+dfsg-2ubuntu6.24 |
| qemu | qemu | >= 0 < 1:8.2.2+ds-0ubuntu1.4 | 1:8.2.2+ds-0ubuntu1.4 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.47+esm4 | 2.0.0+dfsg-2ubuntu1.47+esm4 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.51+esm3 | 1:2.5+dfsg-5ubuntu10.51+esm3 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.42+esm2 | 1:2.11+dfsg-1ubuntu7.42+esm2 |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
qemu vulnerabilities
osv·2024-11-08·CVSS 3.5
CVE-2019-20382 [LOW] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2019-20382)
It was discovered that QEMU incorrectly handled certain memory copy
operations when loading ROM contents. If a user were tricked into running
an untrusted kernel image, a remote attacker could possibly use this issue
to run arbitrary code. This issue only affected Ubuntu 14.04 LTS.
(CVE-2020-13765)
Aviv Sasson discovered that QEMU incorrectly handled Slirp networking. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
denial of service, or possibly execute arbitrary code. This iss
GHSA
GHSA-pf9q-2ff3-67r4: rom_copy() in hw/core/loader
ghsa_unreviewed·2022-05-24
CVE-2020-13765 [MEDIUM] CWE-787 GHSA-pf9q-2ff3-67r4: rom_copy() in hw/core/loader
rom_copy() in hw/core/loader.c in QEMU 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
OSV
qemu vulnerabilities
osv·2020-08-19·CVSS 6.5
CVE-2020-10756 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Ziming Zhang and VictorV discovered that the QEMU SLiRP networking
implementation incorrectly handled replying to certain ICMP echo requests.
An attacker inside a guest could possibly use this issue to leak host
memory to obtain sensitive information. This issue only affected Ubuntu
18.04 LTS. (CVE-2020-10756)
Eric Blake and Xueqiang Wei discovered that the QEMU NDB implementation
incorrectly handled certain requests. A remote attacker could possibly use
this issue to cause QEMU to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2020-10761)
Ziming Zhang discovered that the QEMU SM501 graphics driver incorrectly
handled certain operations. An attacker inside a guest could use this issue
to cause QEMU to crash, resulting in a d
OSV
CVE-2020-13765: rom_copy() in hw/core/loader
osv·2020-06-04·CVSS 5.6
CVE-2020-13765 [MEDIUM] CVE-2020-13765: rom_copy() in hw/core/loader
rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2024-11-08·CVSS 3.5
CVE-2020-8608 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2019-20382)
It was discovered that QEMU incorrectly handled certain memory copy
operations when loading ROM contents. If a user were tricked into running
an untrusted kernel image, a remote attacker could possibly use this issue
to run arbitrary code. This issue only affected Ubuntu 14.04 LTS.
(CVE-2020-13765)
Aviv Sasson discovered that QEMU incorrectly handled Slirp networking. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
de
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2020-08-19·CVSS 6.5
CVE-2020-10756 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Ziming Zhang and VictorV discovered that the QEMU SLiRP networking
implementation incorrectly handled replying to certain ICMP echo requests.
An attacker inside a guest could possibly use this issue to leak host
memory to obtain sensitive information. This issue only affected Ubuntu
18.04 LTS. (CVE-2020-10756)
Eric Blake and Xueqiang Wei discovered that the QEMU NDB implementation
incorrectly handled certain requests. A remote attacker could possibly use
this issue to cause QEMU to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2020-10761)
Ziming Zhang discovered that the QEMU SM501 graphics driver incorrectly
handled certain operations. An attacker inside a guest
Red Hat
QEMU: loader: OOB access while loading registered ROM may lead to code execution
vendor_redhat·2020-05-12·CVSS 5.6
CVE-2020-13765 [MEDIUM] CWE-787 QEMU: loader: OOB access while loading registered ROM may lead to code execution
QEMU: loader: OOB access while loading registered ROM may lead to code execution
rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
An out-of-bound write access flaw was found in the way QEMU loads ROM contents at boot time. This flaw occurs in the rom_copy() routine while loading the contents of a 32-bit -kernel image into memory. Running an untrusted -kernel image may load contents at arbitrary memory locations, potentially leading to code execution with the privileges of the QEMU process.
Statement: In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at t
Debian
CVE-2020-13765: qemu - rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relat...
vendor_debian·2020·CVSS 5.6
CVE-2020-13765 [MEDIUM] CVE-2020-13765: qemu - rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relat...
rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
Scope: local
bookworm: resolved (fixed in 1:4.2-1)
bullseye: resolved (fixed in 1:4.2-1)
forky: resolved (fixed in 1:4.2-1)
sid: resolved (fixed in 1:4.2-1)
trixie: resolved (fixed in 1:4.2-1)
No detection rules found.
No public exploits indexed.
https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=e423455c4f23a1a828901c78fe6d03b7dde79319https://github.com/qemu/qemu/commit/4f1c6cb2f9afafda05eab150fd2bd284edce6676https://lists.debian.org/debian-lts-announce/2020/06/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00020.htmlhttps://security.netapp.com/advisory/ntap-20200619-0006/https://usn.ubuntu.com/4467-1/https://www.openwall.com/lists/oss-security/2020/06/03/6https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=e423455c4f23a1a828901c78fe6d03b7dde79319https://github.com/qemu/qemu/commit/4f1c6cb2f9afafda05eab150fd2bd284edce6676https://lists.debian.org/debian-lts-announce/2020/06/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00020.htmlhttps://security.netapp.com/advisory/ntap-20200619-0006/https://usn.ubuntu.com/4467-1/https://www.openwall.com/lists/oss-security/2020/06/03/6
2020-06-04
Published