CVE-2020-13659: Null Pointer Dereference
Published Jun 2, 2020
·Updated
addressspacemap in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
Affected Software
8 affected componentsFixes available
Qemu Qemu=4.2.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
openSUSE Leap=15.2
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
debian/qemu
1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u41:7.2+dfsg-7+deb12u131:10.0.0+ds-2
Remediation
Patch Available
Event History
Jun 2, 2020
CVE Published
via MITRE·12:50 PM
Data Sourced
via MITRE·12:50 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:39 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:22 AM
RemedyDescriptionSeverityAffected Software
May 2, 2025
Data Sourced
via Debian·01:13 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2020-13659?
CVE-2020-13659 is a vulnerability in QEMU that can trigger a NULL pointer dereference related to BounceBuffer.
2
What is the severity of CVE-2020-13659?
CVE-2020-13659 has a severity value of 2.5, which is considered low.
3
Which software versions are affected by CVE-2020-13659?
CVE-2020-13659 affects QEMU versions 4.2.0 and potentially earlier versions.
4
How can I fix CVE-2020-13659?
To fix CVE-2020-13659, you should update QEMU to version 4.2.0 (or a later version if available) that includes the necessary patches.
5
Where can I find more information about CVE-2020-13659?
You can find more information about CVE-2020-13659 in the references provided: [1] [2] [3].