PT-2020-6466 · Qemu+3 · Qemu+3

Ziming Zhang

·

Published

2020-04-27

·

Updated

2024-06-15

·

CVE-2020-11869

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions QEMU versions 4.0.1 through 4.2.0
Description An integer overflow was found in the way QEMU implemented ATI VGA emulation. This flaw occurs in the ati 2d blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati mm write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
Recommendations For QEMU versions 4.0.1 through 4.2.0, consider disabling the ati 2d blt() function or restricting MMIO write operations through the ati mm write() callback as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1912
ALT-PU-2020-2431
BDU:2021-05170
CVE-2020-11869
OPENSUSE-SU-2024:11287-1
USN-4372-1

Affected Products

Alt Linux
Linuxmint
Qemu
Ubuntu