CVE-2020-27616: Medium severity qemu vulnerability
Published Nov 6, 2020
·Updated
ati2dblt in hw/display/ati2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can crash the QEMU process.
Affected Software
2 affected componentsFixes available
debian/qemu
1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u21:7.2+dfsg-7+deb12u71:9.0.2+ds-21:9.1.0+ds-2
Qemu Qemu=4.2.1
Remediation
Patch Available
Event History
Nov 6, 2020
CVE Published
via MITRE·07:48 AM
Data Sourced
via MITRE·07:48 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:47 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·02:13 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-27616?
CVE-2020-27616 is rated as a medium severity vulnerability due to its potential to crash the QEMU process.
2
How do I fix CVE-2020-27616?
To mitigate CVE-2020-27616, update QEMU to a version later than 4.2.1 that addresses this vulnerability.
3
What software is affected by CVE-2020-27616?
CVE-2020-27616 affects QEMU version 4.2.1 and several specific Debian package versions.
4
Can CVE-2020-27616 be exploited remotely?
Yes, CVE-2020-27616 can be exploited by a guest to crash the QEMU process.
5
What systems should I check for CVE-2020-27616?
Check any systems running QEMU version 4.2.1 or specific Debian package versions for CVE-2020-27616.