Your submission was sent successfully! Close

CVE-2020-13253

Published: 27 May 2020

sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.

Priority

Low

CVSS 3 base score: 5.5

Status

Package Release Status
qemu
Launchpad, Ubuntu, Debian
bionic
Released (1:2.11+dfsg-1ubuntu7.31)
eoan Ignored
(reached end-of-life)
focal
Released (1:4.2-3ubuntu6.4)
groovy Not vulnerable
(1:5.0-5ubuntu4)
hirsute Not vulnerable
(1:5.0-5ubuntu4)
precise Does not exist

trusty
Released (2.0.0+dfsg-2ubuntu1.47+esm1)
upstream Needs triage

xenial
Released (1:2.5+dfsg-5ubuntu10.45)
Patches:
upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=790762e5487114341cccc5bffcec4cb3c022c3cd
qemu-kvm
Launchpad, Ubuntu, Debian
bionic Does not exist

eoan Does not exist

focal Does not exist

groovy Does not exist

hirsute Does not exist

precise Ignored
(end of ESM support, was needs-triage)
trusty Does not exist

upstream Needs triage

xenial Does not exist