Severity
6.3MEDIUMNVD
NVD5.7
EPSS
0.3%
top 46.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30
Latest updateMay 24

Description

A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while doing a multi block SDMA transfer via the sdhci_sdma_transfer_multi_blocks() routine in hw/sd/sdhci.c. A guest user or process could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code with privileges of the QEMU process on the host.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:LExploitability: 2.0 | Impact: 3.7

Affected Packages12 packages

debiandebian/qemu< qemu 1:5.2+dfsg-10 (bookworm)
Debianqemu/qemu< 1:5.2+dfsg-10+3
Ubuntuqemu/qemu< 1:2.5+dfsg-5ubuntu10.48+2
NVDqemu/qemu5.0.0+1
CVEListV5qemu/qemuup to (including) 5.2.0

Also affects: Debian Linux 9.0, Fedora 33, Enterprise Linux 7.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-vrm6-9j6g-w54w: A heap-based buffer overflow was found in QEMU through 52022-05-24
GHSA
GHSA-mx4g-vhmg-3rf6: The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pre2022-05-24
OSV
CVE-2021-3409: The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pre2021-03-23
OSV
CVE-2020-17380: A heap-based buffer overflow was found in QEMU through 52021-01-30
OSV
qemu vulnerabilities2020-11-30

📋Vendor Advisories

7
Microsoft
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation cod2021-03-09
Microsoft
A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while doing a multi block SDMA transfer via the sdhci_sdma_transfer_multi_blocks() ro2021-01-12
Debian
CVE-2021-3409: qemu - The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus ma...2021
Red Hat
QEMU: sdhci: incomplete fix for CVE-2020-17380/CVE-2020-250852020-12-28
Ubuntu
QEMU vulnerabilities2020-11-30

💬Community

1
Bugzilla
CVE-2020-17380 QEMU: heap buffer overflow in sdhci_sdma_transfer_multi_blocks() in hw/sd/sdhci.c2020-07-30