CVE-2020-10702: Medium severity Qemu Qemu vulnerability
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-10702?
CVE-2020-10702 is a vulnerability in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM.
What is the severity of CVE-2020-10702?
The severity of CVE-2020-10702 is medium, with a severity value of 5.5.
Which software is affected by CVE-2020-10702?
QEMU versions between 4.0.0 and 5.0.0 are affected by CVE-2020-10702.
How do I fix CVE-2020-10702?
To fix CVE-2020-10702, update QEMU to version 5.0.0 or higher.
Where can I find more information about CVE-2020-10702?
You can find more information about CVE-2020-10702 at the following references: [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10702), [Ubuntu Security Notices](https://ubuntu.com/security/notices/USN-4372-1), and [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-10702).