[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE-2021-20196 QEMU: block: fdc: null pointer dereference may lead to guest crash
From:       P J P <ppandit () redhat ! com>
Date:       2021-01-28 7:11:04
Message-ID: 75q7866n-1r8s-1np8-sro1-o6268nn87n6 () erqung ! pbz
[Download RAW message or body]

   Hello,

A NULL pointer dereference issue was found in the Floopy disk emulator of 
QEMU. It could occur while processing read/write ioport commands, if the 
selected Floopy drive is not initialised with a block device. A privileged 
guest user could use this flaw to crash the QEMU process on the host resulting 
in DoS scenario.

Upstream patch:
---------------
   -> https://lists.nongnu.org/archive/html/qemu-devel/2021-01/msg05986.html

This issue was reported by Gaoning Pan of Zhejiang University & Ant Security 
Light-Year Lab.

Thank you.
--
Prasad J Pandit / Red Hat Product Security Team
8685 545E B54C 486B C6EB 271E E285 8B5A F050 DE8D

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic