QEMU: vnc: memory leakage upon disconnect
Published Mar 5, 2020
3.5
LOWCVSS 3.1
EPSS 0.87%
Description
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
Affected products
No data.
Configuration 3
- 9.0
- 10.0
Configuration 4
- 16.04
- 18.04
- 19.10
- 20.04
No data.
Red Hat Enterprise Linux 7
qemu-kvm-10:1.5.3-175.el7
Fixed · RHSA-2020:3906
Red Hat Enterprise Linux 7
qemu-kvm-ma-10:2.12.0-48.el7
Fixed · RHSA-2020:3907
Red Hat Enterprise Linux 8
virt-devel:rhel-8020020200601195459.4cda2c84
Fixed · RHSA-2020:2774
Red Hat Enterprise Linux 8
virt:rhel-8020020200601195459.4cda2c84
Fixed · RHSA-2020:2774
Red Hat OpenStack Platform 13.0 (Queens)
qemu-kvm-rhev-10:2.12.0-48.el7_9.1
Fixed · RHSA-2020:4167
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
qemu-kvm-rhev-10:2.12.0-18.el7_6.12
Fixed · RHSA-2020:4167
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
qemu-kvm-rhev-10:2.12.0-48.el7
Fixed · RHSA-2020:3267
Red Hat Virtualization Engine 4.3
qemu-kvm-rhev-10:2.12.0-48.el7
Fixed · RHSA-2020:3267
Red Hat Enterprise Linux 5
kvm
Not affected
Red Hat Enterprise Linux 5
xen
Not affected
Red Hat Enterprise Linux 6
qemu-kvm
Not affected
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.1/qemu-kvm
Affected
Red Hat OpenStack Platform 10 (Newton)
qemu-kvm-rhev
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | qemu-kvm-10:1.5.3-175.el7 | Fixed | RHSA-2020:3906 |
| Red Hat Enterprise Linux 7 | qemu-kvm-ma-10:2.12.0-48.el7 | Fixed | RHSA-2020:3907 |
| Red Hat Enterprise Linux 8 | virt-devel:rhel-8020020200601195459.4cda2c84 | Fixed | RHSA-2020:2774 |
| Red Hat Enterprise Linux 8 | virt:rhel-8020020200601195459.4cda2c84 | Fixed | RHSA-2020:2774 |
| Red Hat OpenStack Platform 13.0 (Queens) | qemu-kvm-rhev-10:2.12.0-48.el7_9.1 | Fixed | RHSA-2020:4167 |
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | qemu-kvm-rhev-10:2.12.0-18.el7_6.12 | Fixed | RHSA-2020:4167 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | qemu-kvm-rhev-10:2.12.0-48.el7 | Fixed | RHSA-2020:3267 |
| Red Hat Virtualization Engine 4.3 | qemu-kvm-rhev-10:2.12.0-48.el7 | Fixed | RHSA-2020:3267 |
| Red Hat Enterprise Linux 5 | kvm | Not affected | n/a |
| Red Hat Enterprise Linux 5 | xen | Not affected | n/a |
| Red Hat Enterprise Linux 6 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.1/qemu-kvm | Affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | qemu-kvm-rhev | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw did not affect the versions of `qemu-kvm` as shipped with Red Hat Enterprise Linux 6 as they did not include the vulnerable code.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.html vendor-advisoryx_refsource_SUSEBroken LinkThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/03/05/1 x_refsource_MISCMailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-20382 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1810390 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10934 Advisory
- https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=6bf21f3d83e95bcc4ba35a7a07cc6655e8b010b0 x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2020/07/msg00020.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-20382
- https://usn.ubuntu.com/4372-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-20382
- https://www.debian.org/security/2020/dsa-4665 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.openwall.com/lists/oss-security/2020/03/05/1
Change history (0)
No recorded changes yet.