CVE-2020-15859

Related Vulnerabilities: CVE-2020-15859  

Debian Bug report logs - #965978
CVE-2020-15859

version graph

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Tue, 21 Jul 2020 19:21:01 UTC

Severity: important

Tags: security

Found in versions qemu/1:5.0-11, qemu/1:5.0-6

Forwarded to https://lists.gnu.org/archive/html/qemu-devel/2020-07/msg05895.html

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org>:
Bug#965978; Package src:qemu. (Tue, 21 Jul 2020 19:21:03 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org>. (Tue, 21 Jul 2020 19:21:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2020-15859
Date: Tue, 21 Jul 2020 21:16:14 +0200
Source: qemu
Severity: important
Tags: security

From oss-security:

---------------------------------------------------------------------------
A use-after-free issue was found in the INTEL 82574 NIC (e1000e) emulator of
the QEMU. It could occur while sending packets if the guest user set the
packet data address to e1000e's MMIO address. A guest user/process could use
this flaw to crash the QEMU process on the host resulting in DoS scenario.

Upstream patch:
----------------
  -> https://lists.gnu.org/archive/html/qemu-devel/2020-07/msg05895.html

Reference:
----------
  -> https://bugs.launchpad.net/qemu/+bug/1886362

This issue was reported by Alexander Bulekov. CVE-2020-15859 assigned via
Mitre.
---------------------------------------------------------------------------

Cheers,
        Moritz



Marked as found in versions qemu/1:5.0-11. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Tue, 21 Jul 2020 20:03:03 GMT) (full text, mbox, link).


Marked as found in versions qemu/1:5.0-6. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Tue, 21 Jul 2020 20:03:03 GMT) (full text, mbox, link).


Set Bug forwarded-to-address to 'https://lists.gnu.org/archive/html/qemu-devel/2020-07/msg05895.html'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Tue, 21 Jul 2020 20:03:04 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jul 22 09:13:06 2020; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.