CVE-2020-25085
published 2020-09-25CVE-2020-25085: QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
PriorityP422medium5CVSS 3.1
AVLACHPRHUINSCCLILAL
EPSS
0.64%
46.9th percentile
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:5.2+dfsg-1 (bookworm) | qemu 1:5.2+dfsg-1 (bookworm) |
| debian | qemu | < qemu 1:5.2+dfsg-10 (bookworm) | qemu 1:5.2+dfsg-10 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | qemu-img-4.2.0-29.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | qemu-img-4.2.0-29.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | qemu-kvm-4.2.0-29.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | qemu-kvm-4.2.0-29.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| qemu | qemu | <= 5.2.0 | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-10 | 1:5.2+dfsg-10 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-1 | 1:5.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-10 | 1:5.2+dfsg-10 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-1 | 1:5.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-10 | 1:5.2+dfsg-10 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-1 | 1:5.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-10 | 1:5.2+dfsg-10 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-1 | 1:5.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.48 | 1:2.5+dfsg-5ubuntu10.48 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.34 | 1:2.11+dfsg-1ubuntu7.34 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.10 | 1:4.2-3ubuntu6.10 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_msrc5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mx4g-vhmg-3rf6: The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pre
ghsa_unreviewed·2022-05-24·CVSS 6.3
CVE-2021-3409 [MEDIUM] CWE-119 GHSA-mx4g-vhmg-3rf6: The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pre
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.
GHSA
GHSA-hr23-r85w-j998: QEMU 5
ghsa_unreviewed·2022-05-24
CVE-2020-25085 [MEDIUM] CWE-787 GHSA-hr23-r85w-j998: QEMU 5
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
OSV
CVE-2021-3409: The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pre
osv·2021-03-23·CVSS 6.3
CVE-2021-3409 [MEDIUM] CVE-2021-3409: The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pre
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.
OSV
qemu vulnerabilities
osv·2020-11-30·CVSS 6.3
CVE-2020-17380 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Alexander Bulekov discovered that QEMU incorrectly handled SDHCI device
emulation. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service, or possibly execute arbitrary
code on the host. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2020-17380)
Sergej Schumilo, Cornelius Aschermann, and Simon Wrner discovered that QEMU
incorrectly handled USB device emulation. An attacker inside the guest
could use this issue to cause QEMU to crash, resulting in a denial of
service. (CVE-2020-25084)
Sergej Schumilo, Cornelius Aschermann, and Simon Wrner discovered that QEMU
incorrectly handled SDHCI device emulation. An attacker inside the guest
could
OSV
CVE-2020-25085: QEMU 5
osv·2020-09-25·CVSS 5.0
CVE-2020-25085 [MEDIUM] CVE-2020-25085: QEMU 5
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
Microsoft
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation cod
vendor_msrc·2021-03-09·CVSS 5.7
CVE-2021-3409 [MEDIUM] CWE-119 The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation cod
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committ
Debian
CVE-2021-3409: qemu - The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus ma...
vendor_debian·2021·CVSS 6.3
CVE-2021-3409 [MEDIUM] CVE-2021-3409: qemu - The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus ma...
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-10)
bullseye: resolved (fixed in 1:5.2+dfsg-10)
forky: resolved (fixed in 1:5.2+dfsg-10)
sid: resolved (fixed in 1:5.2+dfsg-10)
trixie: resolved (fixed in 1:5.2+dfsg-10)
Red Hat
QEMU: sdhci: incomplete fix for CVE-2020-17380/CVE-2020-25085
vendor_redhat·2020-12-28·CVSS 6.3
CVE-2021-3409 [MEDIUM] CWE-119 QEMU: sdhci: incomplete fix for CVE-2020-17380/CVE-2020-25085
QEMU: sdhci: incomplete fix for CVE-2020-17380/CVE-2020-25085
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.
The patch for CVE-2020-17380 and CVE-2020-25085, both involving a heap buffer overflow in the SDHCI controller emulation code of QEMU, was found to be incomplete. A malicious privileged guest could reproduce the same issues with specially crafted input, inducing a bogus transfer and subsequent out-of-bounds read/write access in sdhci
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2020-11-30·CVSS 6.3
CVE-2020-25624 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Alexander Bulekov discovered that QEMU incorrectly handled SDHCI device
emulation. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service, or possibly execute arbitrary
code on the host. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2020-17380)
Sergej Schumilo, Cornelius Aschermann, and Simon Wrner discovered that QEMU
incorrectly handled USB device emulation. An attacker inside the guest
could use this issue to cause QEMU to crash, resulting in a denial of
service. (CVE-2020-25084)
Sergej Schumilo, Cornelius Aschermann, and Simon Wrner discovered that QEMU
incorrectly handle
Red Hat
QEMU: sdhci: out-of-bounds access issue while doing multi block SDMA
vendor_redhat·2020-06-24·CVSS 5.0
CVE-2020-25085 [MEDIUM] CWE-125 QEMU: sdhci: out-of-bounds access issue while doing multi block SDMA
QEMU: sdhci: out-of-bounds access issue while doing multi block SDMA
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
A flaw was found in QEMU. An out-of-bounds read/write access issue was found in the SDHCI Controller emulator of QEMU. It may occur while doing multi block SDMA, if transfer block size exceeds the 's->fifo_buffer[s->buf_maxsz]' size which would leave the current element pointer 's->data_count' pointing out of bounds. This would lead the subsequent DMA r/w operation to an OOB access issue where a guest user/process may use this flaw to crash the QEMU process resulting in DoS scenario. The highest threat from this vulnerability is to data confidentiality and integrity
Debian
CVE-2020-25085: qemu - QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c ...
vendor_debian·2020·CVSS 5.0
CVE-2020-25085 [MEDIUM] CVE-2020-25085: qemu - QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c ...
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-1)
bullseye: resolved (fixed in 1:5.2+dfsg-1)
forky: resolved (fixed in 1:5.2+dfsg-1)
sid: resolved (fixed in 1:5.2+dfsg-1)
trixie: resolved (fixed in 1:5.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25085 QEMU: sdhci: out-of-bounds access issue while doing multi block SDMA
bugzilla·2020-09-16·CVSS 5.0
CVE-2020-25085 [MEDIUM] CVE-2020-25085 QEMU: sdhci: out-of-bounds access issue while doing multi block SDMA
CVE-2020-25085 QEMU: sdhci: out-of-bounds access issue while doing multi block SDMA
An out-of-bounds r/w access issue was found in the SDHCI Controller emulator of QEMU. It may occur while doing multi block SDMA, if transfer block size exceeds the 's->fifo_buffer[s->buf_maxsz]' size. It'd leave the current element pointer 's->data_count' pointing out of bounds. Leading the subsequent DMA r/w operation to OOB access issue. A guest user/process may use this flaw to crash the QEMU process resulting in DoS scenario.
Upstream patches:
-> https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg00733.html
-> https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg01439.html
Reference:
-> https://www.openwall.com/lists/oss-security/2020/09/16/6
Discussion:
Acknowledgments:
Name: Serg
Bugzilla
CVE-2020-25085 qemu: sdhci: out-of-bounds access issue while doing multi block SDMA [fedora-all]
bugzilla·2020-09-16·CVSS 5.0
CVE-2020-25085 [MEDIUM] CVE-2020-25085 qemu: sdhci: out-of-bounds access issue while doing multi block SDMA [fedora-all]
CVE-2020-25085 qemu: sdhci: out-of-bounds access issue while doing multi block SDMA [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2020-17380 QEMU: heap buffer overflow in sdhci_sdma_transfer_multi_blocks() in hw/sd/sdhci.c
bugzilla·2020-07-30·CVSS 6.3
CVE-2020-17380 [MEDIUM] CVE-2020-17380 QEMU: heap buffer overflow in sdhci_sdma_transfer_multi_blocks() in hw/sd/sdhci.c
CVE-2020-17380 QEMU: heap buffer overflow in sdhci_sdma_transfer_multi_blocks() in hw/sd/sdhci.c
A heap-based buffer overflow vulnerability was found in QEMU in the SDHCI device emulation support. It could occur while doing a multi block SDMA transfer via sdhci_sdma_transfer_multi_blocks() routine. A guest user or process could use this flaw to crash the QEMU process on the host resulting in a denial-of-service condition, or potentially execute arbitrary code with privileges of the QEMU process on the host.
Discussion:
Acknowledgments:
Name: Alexander Bulekov
---
Statement:
This flaw did not affect the following versions of QEMU as they did not include support for SDHCI device emulation:
* `qemu-kvm-ma` as shipped with Red Hat Enterprise Linux 7.
* `qemu-kvm-rhev` as shipped with Re
http://www.openwall.com/lists/oss-security/2020/09/16/6http://www.openwall.com/lists/oss-security/2021/03/09/1https://bugs.launchpad.net/qemu/+bug/1892960https://lists.debian.org/debian-lts-announce/2020/11/msg00047.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg00733.htmlhttps://security.netapp.com/advisory/ntap-20201009-0005/http://www.openwall.com/lists/oss-security/2020/09/16/6http://www.openwall.com/lists/oss-security/2021/03/09/1https://bugs.launchpad.net/qemu/+bug/1892960https://lists.debian.org/debian-lts-announce/2020/11/msg00047.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg00733.htmlhttps://security.netapp.com/advisory/ntap-20201009-0005/
2020-09-25
Published