CVE 2020-15863
hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest user or process could use this flaw to crash the QEMU process on the host, resulting in a denial of service or potential privileged code execution. This was fixed in commit 5519724a13664b4
Related bugs and status
CVE-2020-15863 (Candidate) is related to these bugs:
Bug #1749393: sbrk() not working under qemu-user with a PIE-compiled binary?
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1749393 | sbrk() not working under qemu-user with a PIE-compiled binary? | QEMU | Undecided | Fix Released | ||
1749393 | sbrk() not working under qemu-user with a PIE-compiled binary? | qemu (Ubuntu) | Undecided | Fix Released | ||
1749393 | sbrk() not working under qemu-user with a PIE-compiled binary? | qemu (Ubuntu Focal) | Medium | Fix Released |
Bug #1805256: qemu-img hangs on rcu_call_ready_event logic in Aarch64 when converting images
Bug #1887763: new default qemu TCG sizes exceed common CI setups
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1887763 | new default qemu TCG sizes exceed common CI setups | qemu (Ubuntu) | Undecided | Fix Released |
Bug #1897854: groovy qemu-arm-static: /build/qemu-W3R0Rj/qemu-5.0/linux-user/elfload.c:2317: pgb_reserved_va: Assertion `guest_base != 0' failed.
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1897854 | groovy qemu-arm-static: /build/qemu-W3R0Rj/qemu-5.0/linux-user/elfload.c:2317: pgb_reserved_va: Assertion `guest_base != 0' failed. | qemu (Ubuntu) | Undecided | Fix Released | ||
1897854 | groovy qemu-arm-static: /build/qemu-W3R0Rj/qemu-5.0/linux-user/elfload.c:2317: pgb_reserved_va: Assertion `guest_base != 0' failed. | qemu (Ubuntu Groovy) | Undecided | Fix Released |
Bug #1902654: failure to migrate virtual machines with pc-i440fx-wily type to ubuntu 20.04
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1902654 | failure to migrate virtual machines with pc-i440fx-wily type to ubuntu 20.04 | libvirt (Ubuntu) | Undecided | Invalid | ||
1902654 | failure to migrate virtual machines with pc-i440fx-wily type to ubuntu 20.04 | qemu (Ubuntu) | Medium | Fix Released | ||
1902654 | failure to migrate virtual machines with pc-i440fx-wily type to ubuntu 20.04 | qemu (Ubuntu Groovy) | Medium | Fix Released | ||
1902654 | failure to migrate virtual machines with pc-i440fx-wily type to ubuntu 20.04 | qemu (Ubuntu Focal) | Medium | Fix Released |
See the
CVE page on Mitre.org
for more details.