← Back

Qemu

qemu

Vendor: Qemu • 419 CVEs

CVEs (419)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Qemu
2Debian Linux
Qemu
Nov 21, 2024
Sep 25, 2020
N/A· v4
5.3 MEDIUM· v3
4.7 MEDIUM· v2
hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
2Debian
Qemu
2Debian Linux
Qemu
Nov 21, 2024
Sep 25, 2020
N/A· v4
5.0 MEDIUM· v3
4.4 MEDIUM· v2
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
2Debian
Qemu
2Debian Linux
Qemu
Nov 21, 2024
Sep 25, 2020
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.
6Canonical
DebianFedoraproject+3 more
7Debian Linux
Enterprise LinuxFedora+4 more
Nov 21, 2024
Aug 31, 2020
N/A· v4
5.0 MEDIUM· v3
4.4 MEDIUM· v2
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[409...Show more
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of service, or the potential execution of arbitrary code with the privileges of the QEMU process on the host.Show less
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
Nov 21, 2024
Aug 31, 2020
N/A· v4
3.8 LOW· v3
2.1 LOW· v2
In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback....Show more
In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host, resulting in a denial of service.Show less
2Canonical
Qemu
2Qemu
Ubuntu Linux
Nov 21, 2024
Aug 27, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapQemu+1 more
Nov 21, 2024
Aug 11, 2020
N/A· v4
3.8 LOW· v3
2.1 LOW· v2
In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU proc...Show more
In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.Show less
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
Nov 21, 2024
Jul 28, 2020
N/A· v4
5.3 MEDIUM· v3
4.4 MEDIUM· v2
hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest user or process could...Show more
hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest user or process could use this flaw to crash the QEMU process on the host, resulting in a denial of service or potential privileged code execution. This was fixed in commit 5519724a13664b43e225ca05351c60b4468e4555.Show less
2Debian
Qemu
2Debian Linux
Qemu
Nov 21, 2024
Jul 21, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.
2Debian
Qemu
2Debian Linux
Qemu
Nov 21, 2024
Jul 2, 2020
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.
4Canonical
OpensuseQemu+1 more
4Enterprise Linux
LeapQemu+1 more
Nov 21, 2024
Jun 9, 2020
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum...Show more
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.Show less
1Qemu
1Qemu
Nov 21, 2024
Jun 4, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused ever...Show more
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.Show less
3Canonical
OpensuseQemu
3Leap
QemuUbuntu Linux
Nov 21, 2024
Jun 4, 2020
N/A· v4
6.0 MEDIUM· v3
4.9 MEDIUM· v2
ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call.
1Qemu
1Qemu
Nov 21, 2024
Jun 4, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configuration space.
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
Nov 21, 2024
Jun 4, 2020
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
Nov 21, 2024
Jun 2, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapQemu+1 more
Nov 21, 2024
Jun 2, 2020
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapQemu+1 more
Nov 21, 2024
May 28, 2020
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapQemu+1 more
Nov 21, 2024
May 28, 2020
N/A· v4
3.9 LOW· v3
3.3 LOW· v2
In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
Nov 21, 2024
May 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.