Search CVE reports


Toggle filters

111 – 120 of 483 results


CVE-2020-25707

Low priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate is a duplicate of CVE-2020-2891

2 affected packages

qemu-kvm, qemu

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu-kvm Not in release Not in release
qemu Not affected Not affected
Show less packages

CVE-2020-27821

Medium priority
Fixed

A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may...

2 affected packages

qemu, qemu-kvm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Not affected
qemu-kvm Not in release Not in release
Show less packages

CVE-2020-28916

Medium priority
Fixed

hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.

2 affected packages

qemu, qemu-kvm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Fixed
qemu-kvm Not in release Not in release
Show less packages

CVE-2020-29130

Low priority
Fixed

slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

3 affected packages

libslirp, qemu, qemu-kvm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp Not affected Fixed Not in release
qemu Not affected Not affected Not affected
qemu-kvm Not in release Not in release Not in release
Show less packages

CVE-2020-29129

Low priority
Fixed

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

3 affected packages

libslirp, qemu, qemu-kvm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp Not affected Not affected Fixed Not in release
qemu Not affected Not affected Not affected Not affected
qemu-kvm Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-25723

Medium priority

Some fixes available 15 of 16

A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse...

2 affected packages

qemu, qemu-kvm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Fixed Fixed Fixed Fixed
qemu-kvm Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-27617

Low priority

Some fixes available 15 of 16

eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.

2 affected packages

qemu-kvm, qemu

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu-kvm Not in release Not in release Not in release Not in release Not in release
qemu Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2020-27616

Low priority
Fixed

ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can crash the QEMU process.

2 affected packages

qemu, qemu-kvm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Fixed Not affected
qemu-kvm Not in release Not in release
Show less packages

CVE-2020-24352

Low priority
Vulnerable

An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations...

2 affected packages

qemu, qemu-kvm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu Vulnerable Vulnerable Vulnerable Vulnerable Not affected
qemu-kvm Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-25743

Low priority
Vulnerable

hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

2 affected packages

qemu-kvm, qemu

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu-kvm Not in release Not in release Not in release Not in release Not in release
qemu Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages