CVE-2020-28916
published 2020-12-04CVE-2020-28916: hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.65%
47.6th percentile
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:5.2+dfsg-1 (bookworm) | qemu 1:5.2+dfsg-1 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-1 | 1:5.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-1 | 1:5.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-1 | 1:5.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-1 | 1:5.2+dfsg-1 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.49 | 1:2.5+dfsg-5ubuntu10.49 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.35 | 1:2.11+dfsg-1ubuntu7.35 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.12 | 1:4.2-3ubuntu6.12 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_redhat7.1HIGH
vendor_debian5.5MEDIUM
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2021-02-08·CVSS 3.8
CVE-2020-15859 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled memory in iSCSI emulation.
An attacker inside the guest could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-11947)
Alexander Bulekov discovered that QEMU incorrectly handled Intel e1000e
emulation. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2020-15859)
Alexander Bulekov discovered that QEMU incorrectly handled memory region
cache. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS, and Ubunt
Red Hat
QEMU: e1000e: infinite loop scenario in case of null packet descriptor
vendor_redhat·2020-11-12·CVSS 5.5
CVE-2020-28916 [MEDIUM] CWE-835 QEMU: e1000e: infinite loop scenario in case of null packet descriptor
QEMU: e1000e: infinite loop scenario in case of null packet descriptor
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
An infinite loop flaw was found in the e1000e device emulator in QEMU. This issue could occur while receiving packets via the e1000e_write_packet_to_guest() routine, if the receive(RX) descriptor has a NULL buffer address. This flaw allows a privileged guest user to cause a denial of service. The highest threat from this vulnerability is to system availability.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-k
Red Hat
QEMU: infinite loop in e1000e_write_packet_to_guest() in hw/net/e1000e_core.c
vendor_redhat·2020-11-02·CVSS 7.1
CVE-2020-25707 [HIGH] CWE-835 QEMU: infinite loop in e1000e_write_packet_to_guest() in hw/net/e1000e_core.c
QEMU: infinite loop in e1000e_write_packet_to_guest() in hw/net/e1000e_core.c
An infinite loop flaw was found in the e1000e NIC emulation code of QEMU. This issue occurs in the e1000e_write_packet_to_guest() routine while processing bogus RX descriptor data transmitted by the guest. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
Statement: This flaw was found to be a duplicate of CVE-2020-28916. Please see https://access.redhat.com/security/cve/CVE-2020-28916 for information about affected products and security errata.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat
Debian
CVE-2020-28916: qemu - hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor wit...
vendor_debian·2020·CVSS 5.5
CVE-2020-28916 [MEDIUM] CVE-2020-28916: qemu - hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor wit...
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-1)
bullseye: resolved (fixed in 1:5.2+dfsg-1)
forky: resolved (fixed in 1:5.2+dfsg-1)
sid: resolved (fixed in 1:5.2+dfsg-1)
trixie: resolved (fixed in 1:5.2+dfsg-1)
GHSA
GHSA-49q3-9xm4-cpj5: hw/net/e1000e_core
ghsa_unreviewed·2022-05-24
CVE-2020-28916 [MEDIUM] CWE-835 GHSA-49q3-9xm4-cpj5: hw/net/e1000e_core
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
OSV
qemu vulnerabilities
osv·2021-02-08·CVSS 3.8
CVE-2020-11947 [LOW] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled memory in iSCSI emulation.
An attacker inside the guest could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-11947)
Alexander Bulekov discovered that QEMU incorrectly handled Intel e1000e
emulation. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2020-15859)
Alexander Bulekov discovered that QEMU incorrectly handled memory region
cache. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS, and Ubuntu 20.10. (CVE-2020-27821)
Cheol-woo Myung discovered that QE
OSV
CVE-2020-28916: hw/net/e1000e_core
osv·2020-12-04·CVSS 5.5
CVE-2020-28916 [MEDIUM] CVE-2020-28916: hw/net/e1000e_core
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2020/12/01/2https://lists.debian.org/debian-lts-announce/2021/02/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://lists.nongnu.org/archive/html/qemu-devel/2020-11/msg03185.htmlhttp://www.openwall.com/lists/oss-security/2020/12/01/2https://lists.debian.org/debian-lts-announce/2021/02/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://lists.nongnu.org/archive/html/qemu-devel/2020-11/msg03185.html
2020-12-04
Published