cbcvebase.
CVE-2020-29443
published 2021-01-26

CVE-2020-29443: ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.

PriorityP412low3.9CVSS 3.1
AVLACHPRHUINSCCLINAL
EPSS
0.37%
28.9th percentile
ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:5.2+dfsg-11 (bookworm)qemu 1:5.2+dfsg-11 (bookworm)
qemuqemu
qemuqemu>= 0 < 1:5.2+dfsg-111:5.2+dfsg-11
qemuqemu>= 0 < 1:5.2+dfsg-111:5.2+dfsg-11
qemuqemu>= 0 < 1:5.2+dfsg-111:5.2+dfsg-11
qemuqemu>= 0 < 1:5.2+dfsg-111:5.2+dfsg-11
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.491:2.5+dfsg-5ubuntu10.49
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.371:2.11+dfsg-1ubuntu7.37
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.351:2.11+dfsg-1ubuntu7.35
qemuqemu>= 0 < 1:4.2-3ubuntu6.171:4.2-3ubuntu6.17
qemuqemu>= 0 < 1:4.2-3ubuntu6.121:4.2-3ubuntu6.12
ubuntuqemu

CVSS provenance

nvdv3.13.9LOWCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:N/A:P
osv3.9LOW
vendor_debian3.9LOW
vendor_redhat3.9LOW
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.