PT-2020-6474 · Qemu+8 · Qemu+8

Alexander Bulekov

·

Published

2020-05-02

·

Updated

2022-09-23

·

CVE-2020-15859

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU version 4.2.0
Description The issue is related to a use-after-free in the e1000e core of QEMU's hardware emulation, specifically in the hw/net/e1000e core.c file. This can be triggered by a guest OS user sending an e1000e packet with its data address set to the e1000e's MMIO address, potentially leading to a denial of service.
Recommendations For QEMU version 4.2.0, consider disabling the e1000e core functionality until a patch is available to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2021:4191
ALT-PU-2020-1912
ALT-PU-2020-2431
BDU:2021-05192
CESA-2021_4191
CVE-2020-15859
DLA-2560-1
DLA-3099-1
RHSA-2021:4191
RHSA-2021_4191
RLSA-2021:4191
USN-4725-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Qemu
Red Hat
Rocky Linux
Ubuntu