CVE-2020-11947: Buffer Overflow
A heap buffer overflow flaw was found in the iSCSI support of QEMU. This flaw could lead to an out-of-bounds read access and possible information disclosure from the QEMU process memory to a malicious guest. The highest threat from this vulnerability is to data confidentiality.
Other sources
iscsiaioioctlcb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-11947?
The severity of CVE-2020-11947 is low with a severity value of 3.8.
What is the affected software for CVE-2020-11947?
The affected software for CVE-2020-11947 is QEMU version up to exclusive 5.0.0.
What is the vulnerability reference for CVE-2020-11947?
The vulnerability reference for CVE-2020-11947 can be found at the following links: - https://www.cve.org/CVERecord?id=CVE-2020-11947 - https://nvd.nist.gov/vuln/detail/CVE-2020-11947 - https://www.openwall.com/lists/oss-security/2021/01/13/4 - https://bugzilla.redhat.com/show_bug.cgi?id=1912765 - https://access.redhat.com/errata/RHSA-2021:0648
What is the Common Weakness Enumeration (CWE) for CVE-2020-11947?
The Common Weakness Enumeration (CWE) for CVE-2020-11947 includes CWE-119, CWE-131, and CWE-122.
How can I fix CVE-2020-11947?
To fix CVE-2020-11947, update your QEMU software to version 5.0.0 or higher.