CVE-2020-13362: Low severity Qemu Qemu vulnerability
Published May 28, 2020
·Updated
In QEMU 5.0.0 and earlier, megasaslookupframe in hw/scsi/megasas.c h ...
Affected Software
9 affected componentsFixes available
Qemu Qemu<=5.0.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
openSUSE Leap=15.2
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
debian/qemu
1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u51:7.2+dfsg-7+deb12u181:7.2+dfsg-7+deb12u151:10.0.7+ds-0+deb13u11:10.0.2+ds-2+deb13u11:10.2.1+ds-1
Remediation
Event History
May 28, 2020
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
Description
May 30, 2020
Data Sourced
09:54 PM
SeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:39 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:22 AM
RemedyDescriptionSeverityAffected Software
Feb 23, 2026
Data Sourced
via Debian·07:11 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-13362?
The severity of CVE-2020-13362 is high.
2
What software versions are affected by CVE-2020-13362?
QEMU versions up to and including 5.0.0, Debian Linux 8.0, 9.0, and 10.0, openSUSE Leap 15.2, and Canonical Ubuntu Linux 16.04, 18.04, and 20.04 are affected.
3
How does CVE-2020-13362 impact QEMU?
CVE-2020-13362 allows for an out-of-bounds read via a crafted reply_queue_head field from a guest OS user in QEMU.
4
Is there a fix available for CVE-2020-13362?
Yes, a fix is available. Please refer to the provided references for more information.
5
What is the Common Weakness Enumeration (CWE) for CVE-2020-13362?
The CWE for CVE-2020-13362 is CWE-125.