qemu: hw/display/bochs-display.c does not ensure a sufficient PCI config space allocation leading to a buffer overflow involving the PCIe extended config space
Published Mar 10, 2020
5.8
MEDIUMCVSS 3.1
EPSS 0.37%
Description
hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
kvm
Not affected
Red Hat Enterprise Linux 5
xen
Not affected
Red Hat Enterprise Linux 6
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm-ma
Not affected
Red Hat Enterprise Linux 7
qemu-kvm-rhev
Not affected
Red Hat Enterprise Linux 8
virt:rhel/qemu-kvm
Not affected
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.1/qemu-kvm
Not affected
Red Hat OpenStack Platform 10 (Newton)
qemu-kvm-rhev
Not affected
Red Hat OpenStack Platform 13 (Queens)
qemu-kvm-rhev
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kvm | Not affected | n/a |
| Red Hat Enterprise Linux 5 | xen | Not affected | n/a |
| Red Hat Enterprise Linux 6 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-ma | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-rhev | Not affected | n/a |
| Red Hat Enterprise Linux 8 | virt:rhel/qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.1/qemu-kvm | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | qemu-kvm-rhev | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | qemu-kvm-rhev | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw does not affect the module stream`virt:8.1/qemu-kvm` as shipped with RHEL Advanced Virtualization, as it already includes the patch. Several other packages are unaffected because they do not include PCIe support: * `kvm` and `xen` as shipped with Red Hat Enterprise Linux 5 * `qemu-kvm` as shipped with Red Hat Enterprise Linux 6 and 7 * `qemu-kvm-rhev` as shipped with Red Hat Enterprise Linux 7 * `virt:rhel/qemu-kvm` as shipped with Red Hat Enterprise Linux 8 * `qemu-kvm-rhev` as shipped with Red Hat OpenStack Platform 10 and 13
Red Hat mitigation
Use `-device bochs-display` as conventional PCI device only.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.37% (0.00372) | 28.84th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.37% (0.00372) | 31.10th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00042) | 5.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.67% (0.01669) | 53.27th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.50% (0.04504) | 76.47th | v1 |
| Jan 6, 2022 | 4.50% (0.04504) | 76.26th | v1 |
| Jan 5, 2022 | 1.04% (0.01040) | 65.70th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2019-15034 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1812659 Issue Tracking
- https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01959.html x_refsource_MISCMailing ListPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-15034
- https://usn.ubuntu.com/4372-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-15034
- https://www.debian.org/security/2020/dsa-4665 vendor-advisoryx_refsource_DEBIAN
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.html | vendor-advisoryx_refsource_SUSE | |
| https://access.redhat.com/security/cve/CVE-2019-15034 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1812659 | Issue Tracking | |
| https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01959.html | x_refsource_MISCMailing ListPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-15034 | ||
| https://usn.ubuntu.com/4372-1/ | vendor-advisoryx_refsource_UBUNTU | |
| https://www.cve.org/CVERecord?id=CVE-2019-15034 | ||
| https://www.debian.org/security/2020/dsa-4665 | vendor-advisoryx_refsource_DEBIAN |
Change history (0)
No recorded changes yet.