Back

MEDIUM

QEMU: msix: OOB access during mmio operations may lead to DoS

Published Jun 2, 2020

Description

hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.

Affected products

Remediation

Red Hat statement

In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP qemu-kvm-rhev package.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 2, 2020
Updated Aug 4, 2024
Reserved Jun 1, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 1, 2020
ENISA EUVD
Assigner mitre
Published Jun 2, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-5975