CVE-2020-24352 PUBLISHED

An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.

EPSS 0.14% · 33.4th percentile

Risk Scores

EPSS Score
0.14%
33.4th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10qemu1:10.1.0+ds-5ubuntu2, 1:10.1.0+ds-5ubuntu1, 1:10.0.2+ds-1ubuntu2
Ubuntu:22.04:LTSqemu1:6.2+dfsg-2ubuntu6.24, 1:6.2+dfsg-2ubuntu6.23, 1:6.2+dfsg-2ubuntu6.22
Ubuntu:24.04:LTSqemu1:8.2.2+ds-0ubuntu1.11, 1:8.0.4+dfsg-1ubuntu4, 1:8.0.4+dfsg-1ubuntu5
Ubuntu:20.04:LTSqemu1:4.2-3ubuntu6.16, 1:4.2-3ubuntu6.12, 1:4.2-3ubuntu6.11

Timeline

References

Open in Interactive Console →