PT-2020-6466 · Qemu+3 · Qemu+3
Ziming Zhang
·
Published
2020-04-27
·
Updated
2024-06-15
·
CVE-2020-11869
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
QEMU versions 4.0.1 through 4.2.0
Description
An integer overflow was found in the way QEMU implemented ATI VGA emulation. This flaw occurs in the
ati 2d blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati mm write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.Recommendations
For QEMU versions 4.0.1 through 4.2.0, consider disabling the
ati 2d blt() function or restricting MMIO write operations through the ati mm write() callback as a temporary workaround to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Qemu
Ubuntu