CVE-2020-13253 PUBLISHED

sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.

EPSS 0.12% · 30.3th percentile

Risk Scores

EPSS Score
0.12%
30.3th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSqemu*, *, *
Ubuntu:Pro:14.04:LTSqemu2.0.0+dfsg-2ubuntu1.17, 2.0.0+dfsg-2ubuntu1.19, 2.0.0+dfsg-2ubuntu1.20
Ubuntu:16.04:LTSqemu1:2.5+dfsg-5ubuntu10.37, 0, *
Ubuntu:18.04:LTSqemu*, *, 1:2.11+dfsg-1ubuntu7.13

Timeline

References

Open in Interactive Console →