First published: Thu Sep 17 2020(Updated: )
Ziming Zhang, Xiao Wei, Gonglei Arei, and Yanyu Zhang discovered that QEMU incorrectly handled certain USB packets. An attacker inside the guest could use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code on the host. In the default installation, when QEMU is used with libvirt, attackers would be isolated by the libvirt AppArmor profile.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/qemu | <1:4.2-3ubuntu6.6 | 1:4.2-3ubuntu6.6 |
=20.04 | ||
All of | ||
ubuntu/qemu-system | <1:4.2-3ubuntu6.6 | 1:4.2-3ubuntu6.6 |
=20.04 | ||
All of | ||
ubuntu/qemu-system-arm | <1:4.2-3ubuntu6.6 | 1:4.2-3ubuntu6.6 |
=20.04 | ||
All of | ||
ubuntu/qemu-system-mips | <1:4.2-3ubuntu6.6 | 1:4.2-3ubuntu6.6 |
=20.04 | ||
All of | ||
ubuntu/qemu-system-ppc | <1:4.2-3ubuntu6.6 | 1:4.2-3ubuntu6.6 |
=20.04 | ||
All of | ||
ubuntu/qemu-system-s390x | <1:4.2-3ubuntu6.6 | 1:4.2-3ubuntu6.6 |
=20.04 | ||
All of | ||
ubuntu/qemu-system-sparc | <1:4.2-3ubuntu6.6 | 1:4.2-3ubuntu6.6 |
=20.04 | ||
All of | ||
ubuntu/qemu-system-x86 | <1:4.2-3ubuntu6.6 | 1:4.2-3ubuntu6.6 |
=20.04 | ||
All of | ||
ubuntu/qemu-system-x86-microvm | <1:4.2-3ubuntu6.6 | 1:4.2-3ubuntu6.6 |
=20.04 | ||
All of | ||
ubuntu/qemu-system-x86-xen | <1:4.2-3ubuntu6.6 | 1:4.2-3ubuntu6.6 |
=20.04 | ||
All of | ||
ubuntu/qemu | <1:2.11+dfsg-1ubuntu7.32 | 1:2.11+dfsg-1ubuntu7.32 |
=18.04 | ||
All of | ||
ubuntu/qemu-system | <1:2.11+dfsg-1ubuntu7.32 | 1:2.11+dfsg-1ubuntu7.32 |
=18.04 | ||
All of | ||
ubuntu/qemu-system-arm | <1:2.11+dfsg-1ubuntu7.32 | 1:2.11+dfsg-1ubuntu7.32 |
=18.04 | ||
All of | ||
ubuntu/qemu-system-mips | <1:2.11+dfsg-1ubuntu7.32 | 1:2.11+dfsg-1ubuntu7.32 |
=18.04 | ||
All of | ||
ubuntu/qemu-system-ppc | <1:2.11+dfsg-1ubuntu7.32 | 1:2.11+dfsg-1ubuntu7.32 |
=18.04 | ||
All of | ||
ubuntu/qemu-system-s390x | <1:2.11+dfsg-1ubuntu7.32 | 1:2.11+dfsg-1ubuntu7.32 |
=18.04 | ||
All of | ||
ubuntu/qemu-system-sparc | <1:2.11+dfsg-1ubuntu7.32 | 1:2.11+dfsg-1ubuntu7.32 |
=18.04 | ||
All of | ||
ubuntu/qemu-system-x86 | <1:2.11+dfsg-1ubuntu7.32 | 1:2.11+dfsg-1ubuntu7.32 |
=18.04 | ||
All of | ||
ubuntu/qemu | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-block-extra | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-guest-agent | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-kvm | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-system | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-system-aarch64 | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-system-arm | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-system-common | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-system-mips | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-system-misc | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-system-ppc | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-system-s390x | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-system-sparc | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-system-x86 | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-user | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-user-binfmt | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-user-static | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 | ||
All of | ||
ubuntu/qemu-utils | <1:2.5+dfsg-5ubuntu10.46 | 1:2.5+dfsg-5ubuntu10.46 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.