PT-2020-5186 · Qemu+4 · Qemu+4

Published

2020-07-25

·

Updated

2022-09-30

·

CVE-2020-15863

CVSS v3.1

5.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 07-20-2020
Description The issue is related to a buffer overflow in the XGMAC Ethernet controller, specifically in the xgmac enet send function. This occurs during packet transmission and affects the highbank and midway emulated machines. Exploitation of this issue could allow an attacker to access protected information, compromise its integrity, and cause a denial of service or potentially execute privileged code.
Recommendations For QEMU versions prior to 07-20-2020, update to a version that includes the fix committed in 5519724a13664b43e225ca05351c60b4468e4555 to resolve the issue. As a temporary workaround, consider restricting access to the XGMAC Ethernet controller functionality to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2595
ALT-PU-2020-3332
ALT-PU-2020-3381
ALT-PU-2021-1880
ALT-PU-2021-1964
BDU:2020-05805
CVE-2020-15863
DLA-2288-1
DSA-4760-1
OPENSUSE-SU-2020:1664-1
OPENSUSE-SU-2020_1664-1
SUSE-SU-2020:2743-1
SUSE-SU-2020:2877-1
SUSE-SU-2021:1240-1
SUSE-SU-2021:1241-1
SUSE-SU-2021:1244-1
SUSE-SU-2021:1245-1
SUSE-SU-2021:1305-1
SUSE-SU-2021:14772-1
SUSE-SU-2021:14774-1
SUSE-SU-2021_14772-1
USN-4467-1
USN-4467-3

Affected Products

Alt Linux
Linuxmint
Qemu
Suse
Ubuntu