CVE-2020-13800: Medium severity Qemu Qemu vulnerability
Published Jun 4, 2020
·Updated
ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mmindex value during an atimmread or atimmwrite call.
Affected Software
6 affected componentsFixes available
Qemu Qemu=4.2.0
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
openSUSE Leap=15.2
debian/qemu
1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u51:7.2+dfsg-7+deb12u181:7.2+dfsg-7+deb12u151:10.0.7+ds-0+deb13u11:10.0.2+ds-2+deb13u11:10.2.1+ds-1
Remediation
Event History
Jun 4, 2020
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:39 PM
Description
Feb 23, 2026
Data Sourced
via Ubuntu·06:23 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:24 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2020-13800?
CVE-2020-13800 refers to a vulnerability in QEMU 4.2.0 that allows guest OS users to trigger infinite recursion.
2
How can the ati-vga vulnerability in QEMU be exploited?
The vulnerability can be exploited by guest OS users through a crafted mm_index value during an ati_mm_read or ati_mm_write call.
3
What is the severity of CVE-2020-13800?
The severity of CVE-2020-13800 is medium.
4
Which software versions are affected by CVE-2020-13800?
QEMU 4.2.0 is affected by this vulnerability.
5
How can I fix CVE-2020-13800?
To fix CVE-2020-13800, users should update to version 1:4.2-3ubuntu6.4 of QEMU on Ubuntu or follow the patch provided by the vendor.