CVE-2020-27821
published 2020-12-08CVE-2020-27821: A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write…
PriorityP423medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
EPSS
0.36%
28.6th percentile
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:5.2+dfsg-3 (bookworm) | qemu 1:5.2+dfsg-3 (bookworm) |
| msrc | cm1_qemu-kvm_4.2.0-23_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | < 5.2.0 | 5.2.0 |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-3 | 1:5.2+dfsg-3 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-3 | 1:5.2+dfsg-3 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-3 | 1:5.2+dfsg-3 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-3 | 1:5.2+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.49 | 1:2.5+dfsg-5ubuntu10.49 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.35 | 1:2.11+dfsg-1ubuntu7.35 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.12 | 1:4.2-3ubuntu6.12 |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_msrc6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2021-02-08·CVSS 3.8
CVE-2020-15859 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled memory in iSCSI emulation.
An attacker inside the guest could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-11947)
Alexander Bulekov discovered that QEMU incorrectly handled Intel e1000e
emulation. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2020-15859)
Alexander Bulekov discovered that QEMU incorrectly handled memory region
cache. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS, and Ubunt
Microsoft
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMI
vendor_msrc·2020-12-08·CVSS 6.0
CVE-2020-27821 [MEDIUM] CWE-787 A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMI
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work
Red Hat
QEMU: heap buffer overflow in msix_table_mmio_write() in hw/pci/msix.c
vendor_redhat·2020-12-03·CVSS 6.0
CVE-2020-27821 [MEDIUM] CWE-787 QEMU: heap buffer overflow in msix_table_mmio_write() in hw/pci/msix.c
QEMU: heap buffer overflow in msix_table_mmio_write() in hw/pci/msix.c
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service.
Statement: This flaw did not affect th
Debian
CVE-2020-27821: qemu - A flaw was found in the memory management API of QEMU during the initialization ...
vendor_debian·2020·CVSS 6.0
CVE-2020-27821 [MEDIUM] CVE-2020-27821: qemu - A flaw was found in the memory management API of QEMU during the initialization ...
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-3)
bullseye: resolved (fixed in 1:5.2+dfsg-3)
forky: resolved (fixed in 1:5.2+dfsg-3)
sid: resolved (fixed in 1:5.2+dfsg-3)
trixie: resolved (fixed in 1:5.2+dfsg-3)
GHSA
GHSA-7p47-wfc3-mcqv: A flaw was found in the memory management API of QEMU during the initialization of a memory region cache
ghsa_unreviewed·2022-05-24
CVE-2020-27821 [MEDIUM] CWE-787 GHSA-7p47-wfc3-mcqv: A flaw was found in the memory management API of QEMU during the initialization of a memory region cache
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.
OSV
qemu vulnerabilities
osv·2021-02-08·CVSS 3.8
CVE-2020-11947 [LOW] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled memory in iSCSI emulation.
An attacker inside the guest could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-11947)
Alexander Bulekov discovered that QEMU incorrectly handled Intel e1000e
emulation. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2020-15859)
Alexander Bulekov discovered that QEMU incorrectly handled memory region
cache. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS, and Ubuntu 20.10. (CVE-2020-27821)
Cheol-woo Myung discovered that QE
OSV
CVE-2020-27821: A flaw was found in the memory management API of QEMU during the initialization of a memory region cache
osv·2020-12-08·CVSS 6.0
CVE-2020-27821 [MEDIUM] CVE-2020-27821: A flaw was found in the memory management API of QEMU during the initialization of a memory region cache
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2020/12/16/6https://bugzilla.redhat.com/show_bug.cgi?id=1902651https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.netapp.com/advisory/ntap-20210115-0006/http://www.openwall.com/lists/oss-security/2020/12/16/6https://bugzilla.redhat.com/show_bug.cgi?id=1902651https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://security.netapp.com/advisory/ntap-20210115-0006/
2020-12-08
Published