First published: Fri Nov 06 2020(Updated: )
ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can crash the QEMU process.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/qemu | 1:5.2+dfsg-11+deb11u3 1:5.2+dfsg-11+deb11u2 1:7.2+dfsg-7+deb12u7 1:9.0.2+ds-2 1:9.1.0+ds-2 | |
QEMU KVM | =4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27616 is rated as a medium severity vulnerability due to its potential to crash the QEMU process.
To mitigate CVE-2020-27616, update QEMU to a version later than 4.2.1 that addresses this vulnerability.
CVE-2020-27616 affects QEMU version 4.2.1 and several specific Debian package versions.
Yes, CVE-2020-27616 can be exploited by a guest to crash the QEMU process.
Check any systems running QEMU version 4.2.1 or specific Debian package versions for CVE-2020-27616.