CVE-2020-13754 PUBLISHED

hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.

EPSS 0.03% · 8.7th percentile

Risk Scores

EPSS Score
0.03%
8.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSqemu1:2.11+dfsg-1ubuntu7.29, 1:2.11+dfsg-1ubuntu7.28, 1:2.11+dfsg-1ubuntu7.27
Ubuntu:Pro:14.04:LTSqemu2.0.0+dfsg-2ubuntu1.10, 2.0.0+dfsg-2ubuntu1.11, 2.0.0+dfsg-2ubuntu1.13
Ubuntu:20.04:LTSqemu0, 1:4.0+dfsg-0ubuntu9, 1:4.0+dfsg-0ubuntu10
Ubuntu:16.04:LTSqemu1:2.5+dfsg-5ubuntu10.40, 1:2.5+dfsg-5ubuntu10.41, 1:2.5+dfsg-5ubuntu10.42

Timeline

References

Open in Interactive Console →