qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Bug 1880822] [NEW] CVE-2020-13253 QEMU: sd: OOB access could crash the guest resulting in DoS
@ 2020-05-27  7:10 P J P
  2020-05-27  7:15 ` [Bug 1880822] " P J P
                   ` (8 more replies)
  0 siblings, 9 replies; 17+ messages in thread
From: P J P @ 2020-05-27  7:10 UTC (permalink / raw)
  To: qemu-devel

*** This bug is a security vulnerability ***

Public security bug reported:

An out-of-bounds read access issue was found in the SD Memory Card
emulator of the QEMU. It occurs while performing block write commands
via sdhci_write(), if a guest user has sent 'address' which is OOB of
's->wp_groups'. A guest user/process may use this flaw to crash the QEMU
process resulting in DoS.

** Affects: qemu
     Importance: Undecided
         Status: New


** Tags: cve qemu security

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-13253

-- 
You received this bug notification because you are a member of qemu-
devel-ml, which is subscribed to QEMU.
https://bugs.launchpad.net/bugs/1880822

Title:
  CVE-2020-13253 QEMU: sd: OOB access could crash the guest resulting in
  DoS

Status in QEMU:
  New

Bug description:
  An out-of-bounds read access issue was found in the SD Memory Card
  emulator of the QEMU. It occurs while performing block write commands
  via sdhci_write(), if a guest user has sent 'address' which is OOB of
  's->wp_groups'. A guest user/process may use this flaw to crash the
  QEMU process resulting in DoS.

To manage notifications about this bug go to:
https://bugs.launchpad.net/qemu/+bug/1880822/+subscriptions


^ permalink raw reply	[flat|nested] 17+ messages in thread

end of thread, other threads:[~2020-08-20 14:53 UTC | newest]

Thread overview: 17+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2020-05-27  7:10 [Bug 1880822] [NEW] CVE-2020-13253 QEMU: sd: OOB access could crash the guest resulting in DoS P J P
2020-05-27  7:15 ` [Bug 1880822] " P J P
2020-05-27  7:18 ` P J P
2020-05-27  7:28 ` Philippe Mathieu-Daudé
2020-06-04 15:02 ` Philippe Mathieu-Daudé
2020-06-04 17:34 ` [PATCH] hw/sd/sdcard: Verify CMD24 (Block Write) address is valid Philippe Mathieu-Daudé
2020-06-04 17:34   ` [Bug 1880822] " Philippe Mathieu-Daudé
2020-06-04 18:03   ` Paolo Bonzini
2020-06-04 18:20     ` Philippe Mathieu-Daudé
2020-06-04 18:20       ` [Bug 1880822] " Philippe Mathieu-Daudé
2020-06-04 18:25 ` [PATCH v2] " Philippe Mathieu-Daudé
2020-06-04 18:25   ` [Bug 1880822] " Philippe Mathieu-Daudé
2020-06-05  8:34   ` Philippe Mathieu-Daudé
2020-06-05  8:34     ` [Bug 1880822] " Philippe Mathieu-Daudé
2020-06-05 11:12 ` [Bug 1880822] Re: CVE-2020-13253 QEMU: sd: OOB access could crash the guest resulting in DoS Philippe Mathieu-Daudé
2020-07-16 15:53 ` Philippe Mathieu-Daudé
2020-08-20 14:41 ` Thomas Huth

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).