PT-2020-5305 · Qemu+8 · Qemu+8

Prasad J Pandit

·

Published

2019-12-10

·

Updated

2024-11-08

·

CVE-2019-20382

CVSS v3.1

3.5

Low

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions QEMU version 4.1.0
Description The issue is related to a memory leak in the zrle compress data function during a VNC disconnect operation due to the misuse of libz. This results in memory allocated in deflateInit2 not being freed in deflateEnd, potentially allowing a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For QEMU version 4.1.0, consider updating to a version where the zrle compress data function is properly handled to prevent memory leaks. As a temporary workaround, consider restricting access to the VNC disconnect operation to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Leak

Weakness Enumeration

Related Identifiers

ALSA-2020:2774
ALT-PU-2019-3257
ALT-PU-2019-3286
ALT-PU-2020-1425
ALT-PU-2020-1463
BDU:2021-00071
CESA-2020_2774
CESA-2020_3906
CVE-2019-20382
DLA-2288-1
DSA-4665-1
OPENSUSE-SU-2020:0468-1
OPENSUSE-SU-2020_0468-1
RHSA-2020:2774
RHSA-2020:3267
RHSA-2020:3906
RHSA-2020:3907
RHSA-2020:4167
RHSA-2020_2774
RHSA-2020_3906
RHSA-2020_3907
RLSA-2020:2774
SUSE-SU-2020:0844-1
SUSE-SU-2020:0845-1
SUSE-SU-2020:1501-1
SUSE-SU-2020:1523-1
SUSE-SU-2020_1501-1
SUSE-SU-2020_1523-1
USN-4372-1
USN-7094-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Qemu
Red Hat
Rocky Linux
Suse
Ubuntu