cbcvebase.

Debian Qemu vulnerabilities

424 known vulnerabilities affecting debian/qemu.

Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1

Vulnerabilities

Page 21 of 22
CVE-2020-11947P4LOWCVSS 3.8fixed in qemu 1:4.2-7 (bookworm)2020
CVE-2020-11947 [LOW] CVE-2020-11947: qemu - iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-r... iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker. Scope: local bookworm: resolved (fixed in 1:4.2-7) bullseye: resolved (fixed in 1:4.2-7) forky: resolved (fixed in 1:4.2-7) sid: resolved (fixed in 1:4.2-7) trixie: resolved (fixed in 1:4.2-7)
debian
CVE-2021-20263P4LOWCVSS 3.3fixed in qemu 1:5.2+dfsg-9 (bookworm)2021
CVE-2021-20263 [LOW] CVE-2021-20263: qemu - A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU.... A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.
debian
CVE-2020-11869P4LOWCVSS 3.3fixed in qemu 1:5.0-1 (bookworm)2020
CVE-2020-11869 [LOW] CVE-2020-11869: qemu - An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemen... An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service. Scope: local bookworm: res
debian
CVE-2020-13362P4LOWCVSS 3.2fixed in qemu 1:5.0-6 (bookworm)2020
CVE-2020-13362 [LOW] CVE-2020-13362: qemu - In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-... In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user. Scope: local bookworm: resolved (fixed in 1:5.0-6) bullseye: resolved (fixed in 1:5.0-6) forky: resolved (fixed in 1:5.0-6) sid: resolved (fixed in 1:5.0-6) trixie: resolved (fixed in 1:5.0-6)
debian
CVE-2019-20382P4LOWCVSS 3.5fixed in qemu 1:4.2-1 (bookworm)2019
CVE-2019-20382 [LOW] CVE-2019-20382: qemu - QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a... QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd. Scope: local bookworm: resolved (fixed in 1:4.2-1) bullseye: resolved (fixed in 1:4.2-1) forky: resolved (fixed in 1:4.2-1) sid: resolved (fixed in 1
debian
CVE-2019-8934P4LOWCVSS 3.3fixed in qemu 1:4.1-1 (bookworm)2019
CVE-2019-8934 [LOW] CVE-2019-8934: qemu - hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hyp... hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest. Scope: local bookworm: resolved (fixed in 1:4.1-1) bullseye: resolved (fixed in 1:4.1-1) forky: resolved (fixed in 1:4.1-1) sid: resolved (fixed in 1:4.1-1) trixie: resolved (fixed in 1:4
debian
CVE-2020-15859P4LOWCVSS 3.3fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-15859 [LOW] CVE-2020-15859: qemu - QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user ... QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address. Scope: local bookworm: resolved (fixed in 1:5.2+dfsg-1) bullseye: resolved (fixed in 1:5.2+dfsg-1) forky: resolved (fixed in 1:5.2+dfsg-1) sid: resolved (fixed in 1:5.2+dfsg-1) trixie: resolved (fixed in 1
debian
CVE-2016-9908P4LOWCVSS 3.3fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9908 [LOW] CVE-2016-9908: qemu - Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulne... Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest user/process could use this flaw to leak contents of the host memory bytes. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1) for
debian
CVE-2021-20203P4LOWCVSS 3.2fixed in qemu 1:6.2+dfsg-1 (bookworm)2021
CVE-2021-20203 [LOW] CVE-2021-20203: qemu - An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for ... An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario. Scope: local bookworm: resolved (fixed in 1:6.2+dfsg-1) bullsey
debian
CVE-2021-3392P4LOWCVSS 3.2fixed in qemu 1:5.2+dfsg-10 (bookworm)2021
CVE-2021-3392 [LOW] CVE-2021-3392: qemu - A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occ... A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between
debian
CVE-2020-14394P4LOWCVSS 3.2fixed in qemu 1:7.1+dfsg-1 (bookworm)2020
CVE-2020-14394 [LOW] CVE-2020-14394: qemu - An infinite loop flaw was found in the USB xHCI controller emulation of QEMU whi... An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service. Scope: local bookworm: resolved (fixed in 1:7.1+dfsg-1) bullseye: resolved (fixed in 1:5.2+dfsg-11+deb11u3) forky
debian
CVE-2020-14415P4LOWCVSS 3.3fixed in qemu 1:5.0-1 (bookworm)2020
CVE-2020-14415 [LOW] CVE-2020-14415: qemu - oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position. oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position. Scope: local bookworm: resolved (fixed in 1:5.0-1) bullseye: resolved (fixed in 1:5.0-1) forky: resolved (fixed in 1:5.0-1) sid: resolved (fixed in 1:5.0-1) trixie: resolved (fixed in 1:5.0-1)
debian
CVE-2020-25723P4LOWCVSS 3.2fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-25723 [LOW] CVE-2020-25723: qemu - A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It... A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host, resulting in a denial of service. Scope: local bookworm: resolved
debian
CVE-2020-25084P4LOWCVSS 3.2fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-25084 [LOW] CVE-2020-25084: qemu - QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map ... QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked. Scope: local bookworm: resolved (fixed in 1:5.2+dfsg-1) bullseye: resolved (fixed in 1:5.2+dfsg-1) forky: resolved (fixed in 1:5.2+dfsg-1) sid: resolved (fixed in 1:5.2+dfsg-1) trixie: resolved (fixed in 1:5.2+dfsg-1)
debian
CVE-2013-4377P4LOWCVSS 2.3fixed in qemu 1.7.0+dfsg-4 (bookworm)2013
CVE-2013-4377 [LOW] CVE-2013-4377: qemu - Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 thro... Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 through 1.6.0 allows local users to cause a denial of service (daemon crash) by "hot-unplugging" a virtio device. Scope: local bookworm: resolved (fixed in 1.7.0+dfsg-4) bullseye: resolved (fixed in 1.7.0+dfsg-4) forky: resolved (fixed in 1.7.0+dfsg-4) sid: resolved (fixed in 1.7.0+dfsg-4) trixie:
debian
CVE-2022-26354P4LOWCVSS 3.2fixed in qemu 1:7.0+dfsg-1 (bookworm)2022
CVE-2022-26354 [LOW] CVE-2022-26354: qemu - A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid... A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0. Scope: local bookworm: resolved (fixed in 1:7.0+dfsg-1) bullseye: resolved (fixed in 1:5.2+dfsg-11+deb11u2) forky: resolved (fixed
debian
CVE-2015-4037P4LOWCVSS 1.9fixed in qemu 1:2.3+dfsg-5 (bookworm)2015
CVE-2015-4037 [LOW] CVE-2015-4037: qemu - The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporar... The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program. Scope: local bookworm: resolved (fixed in 1:2.3+dfsg-5) bullseye: resolved (fixed in 1:2.3+dfsg-5) forky: resolved (fixed in 1:2
debian
CVE-2013-4375P4LOWCVSS 2.7fixed in qemu 1.7.0+dfsg-1 (bookworm)2013
CVE-2013-4375 [LOW] CVE-2013-4375: qemu - The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and q... The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors. Scope: local bookworm: resolved (fixed in 1.7.0+dfsg-1) bullseye: resolved (fixed in 1.7.0+dfsg-1) forky: resolved (fixed in 1.7.0+dfsg-1) sid: resolve
debian
CVE-2014-3640P4LOWCVSS 2.1fixed in qemu 2.1+dfsg-5 (bookworm)2014
CVE-2014-3640 [LOW] CVE-2014-3640: qemu - The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to ... The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket. Scope: local bookworm: resolved (fixed in 2.1+dfsg-5) bullseye: resolved (fixed in 2.1+dfsg-5) forky: resolved (fixed
debian
CVE-2020-13659P4LOWCVSS 2.5fixed in qemu 1:5.0-6 (bookworm)2020
CVE-2020-13659 [LOW] CVE-2020-13659: qemu - address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference... address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer. Scope: local bookworm: resolved (fixed in 1:5.0-6) bullseye: resolved (fixed in 1:5.0-6) forky: resolved (fixed in 1:5.0-6) sid: resolved (fixed in 1:5.0-6) trixie: resolved (fixed in 1:5.0-6)
debian
Debian Qemu vulnerabilities | cvebase