hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qemu | Qemu | * | 2.8.1.1 (including) |
Qemu | Qemu | 2.9.0-rc0 (including) | 2.9.0-rc0 (including) |
Red Hat Enterprise Linux 6 | RedHat | qemu-kvm-2:0.12.1.2-2.503.el6_9.3 | * |
Red Hat Enterprise Linux 7 | RedHat | qemu-kvm-10:1.5.3-126.el7_3.9 | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.503.el6_9.3 | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat OpenStack Platform 10.0 (Newton) | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat OpenStack Platform 8.0 (Liberty) | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat OpenStack Platform 9.0 (Mitaka) | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.9 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.10 | * |
RHEV 3.X Hypervisor and Agents for RHEL-6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.503.el6_9.3 | * |
RHEV 3.X Hypervisor and Agents for RHEL-7 | RedHat | qemu-kvm-rhev-10:2.6.0-28.el7_3.10 | * |
Qemu | Ubuntu | artful | * |
Qemu | Ubuntu | bionic | * |
Qemu | Ubuntu | cosmic | * |
Qemu | Ubuntu | devel | * |
Qemu | Ubuntu | disco | * |
Qemu | Ubuntu | eoan | * |
Qemu | Ubuntu | focal | * |
Qemu | Ubuntu | groovy | * |
Qemu | Ubuntu | hirsute | * |
Qemu | Ubuntu | trusty | * |
Qemu | Ubuntu | xenial | * |
Qemu | Ubuntu | yakkety | * |
Qemu | Ubuntu | zesty | * |
Qemu-kvm | Ubuntu | precise | * |
Qemu-kvm | Ubuntu | precise/esm | * |