CVE-2020-29443: Low severity qemu vulnerability
An out-of-bounds read access issue was found in the ATAPI Emulator of QEMU. It occurs while processing ATAPI read command if logical block address(LBA) is set an invalid value. A guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
Upstream patch: --------------- -> https://lists.gnu.org/archive/html/qemu-devel/2021-01/msg04255.html -> https://git.qemu.org/?p=qemu.git;a=commit;h=813212288970c39b1800f63e83ac6e96588095c6
Other sources
An out-of-bounds read-access flaw was found in the ATAPI Emulator of QEMU. This issue occurs while processing the ATAPI read command if the logical block address(LBA) is set to an invalid value. A guest user may use this flaw to crash the QEMU process on the host resulting in a denial of service.
ideatapicmdreplyend in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-29443?
CVE-2020-29443 is an out-of-bounds read-access vulnerability in the ATAPI Emulator of QEMU.
How does CVE-2020-29443 impact QEMU?
CVE-2020-29443 allows a guest user to crash the QEMU process on the host, resulting in a denial of service.
Which versions of QEMU are affected by CVE-2020-29443?
QEMU version 5.1.0 is affected by CVE-2020-29443.
How can I fix CVE-2020-29443?
To fix CVE-2020-29443, update QEMU to version 5.1.1 or later.
Is CVE-2020-29443 a high severity vulnerability?
No, CVE-2020-29443 has a severity rating of medium.