Severity
5.7MEDIUMNVD
NVD5.0OSV6.3OSV5.0
EPSS
0.2%
top 63.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25
Latest updateMay 24

Description

QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:LExploitability: 0.8 | Impact: 3.7

Affected Packages8 packages

debiandebian/qemu< qemu 1:5.2+dfsg-1 (bookworm)+1
Debianqemu/qemu< 1:5.2+dfsg-10+7
Ubuntuqemu/qemu< 1:2.5+dfsg-5ubuntu10.48+2
NVDqemu/qemu5.2.0+1

Also affects: Debian Linux 10.0, 9.0, Fedora 33, Enterprise Linux 7.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-mx4g-vhmg-3rf6: The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pre2022-05-24
GHSA
GHSA-hr23-r85w-j998: QEMU 52022-05-24
OSV
CVE-2021-3409: The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pre2021-03-23
OSV
qemu vulnerabilities2020-11-30
OSV
CVE-2020-25085: QEMU 52020-09-25

📋Vendor Advisories

6
Microsoft
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation cod2021-03-09
Debian
CVE-2021-3409: qemu - The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus ma...2021
Red Hat
QEMU: sdhci: incomplete fix for CVE-2020-17380/CVE-2020-250852020-12-28
Ubuntu
QEMU vulnerabilities2020-11-30
Red Hat
QEMU: sdhci: out-of-bounds access issue while doing multi block SDMA2020-06-24

💬Community

3
Bugzilla
CVE-2020-25085 QEMU: sdhci: out-of-bounds access issue while doing multi block SDMA2020-09-16
Bugzilla
CVE-2020-25085 qemu: sdhci: out-of-bounds access issue while doing multi block SDMA [fedora-all]2020-09-16
Bugzilla
CVE-2020-17380 QEMU: heap buffer overflow in sdhci_sdma_transfer_multi_blocks() in hw/sd/sdhci.c2020-07-30