CVE-2020-15469: Null Pointer Dereference
In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-15469?
CVE-2020-15469 is a vulnerability in QEMU 4.2.0 that could lead to a NULL pointer dereference due to a lack of read/write callback methods in a MemoryRegionOps object.
How severe is CVE-2020-15469?
CVE-2020-15469 has a severity level of 2.3, which is considered low.
What software versions are affected by CVE-2020-15469?
QEMU versions up to 5.0.1, Debian Linux 9.0, and Debian Linux 10.0 are affected by CVE-2020-15469.
How can I fix CVE-2020-15469?
To fix CVE-2020-15469, update QEMU to a version that includes the necessary read/write callback methods and apply any available patches or updates for your specific distribution.
Where can I find more information about CVE-2020-15469?
You can find more information about CVE-2020-15469 on the Openwall and QEMU mailing lists, as well as the Debian LTS announcement.