CVE 2020-13791
hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configuration space.
Related bugs and status
CVE-2020-13791 (Candidate) is related to these bugs:
Bug #1749393: sbrk() not working under qemu-user with a PIE-compiled binary?
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1749393 | sbrk() not working under qemu-user with a PIE-compiled binary? | QEMU | Undecided | Fix Released | ||
1749393 | sbrk() not working under qemu-user with a PIE-compiled binary? | qemu (Ubuntu) | Undecided | Fix Released | ||
1749393 | sbrk() not working under qemu-user with a PIE-compiled binary? | qemu (Ubuntu Focal) | Medium | Fix Released |
Bug #1887763: new default qemu TCG sizes exceed common CI setups
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1887763 | new default qemu TCG sizes exceed common CI setups | qemu (Ubuntu) | Undecided | Fix Released |
Bug #1897854: groovy qemu-arm-static: /build/qemu-W3R0Rj/qemu-5.0/linux-user/elfload.c:2317: pgb_reserved_va: Assertion `guest_base != 0' failed.
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1897854 | groovy qemu-arm-static: /build/qemu-W3R0Rj/qemu-5.0/linux-user/elfload.c:2317: pgb_reserved_va: Assertion `guest_base != 0' failed. | qemu (Ubuntu) | Undecided | Fix Released | ||
1897854 | groovy qemu-arm-static: /build/qemu-W3R0Rj/qemu-5.0/linux-user/elfload.c:2317: pgb_reserved_va: Assertion `guest_base != 0' failed. | qemu (Ubuntu Groovy) | Undecided | Fix Released |
Bug #1902654: failure to migrate virtual machines with pc-i440fx-wily type to ubuntu 20.04
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1902654 | failure to migrate virtual machines with pc-i440fx-wily type to ubuntu 20.04 | libvirt (Ubuntu) | Undecided | Invalid | ||
1902654 | failure to migrate virtual machines with pc-i440fx-wily type to ubuntu 20.04 | qemu (Ubuntu) | Medium | Fix Released | ||
1902654 | failure to migrate virtual machines with pc-i440fx-wily type to ubuntu 20.04 | qemu (Ubuntu Groovy) | Medium | Fix Released | ||
1902654 | failure to migrate virtual machines with pc-i440fx-wily type to ubuntu 20.04 | qemu (Ubuntu Focal) | Medium | Fix Released |
See the
CVE page on Mitre.org
for more details.