CVE-2020-25085

Name
CVE-2020-25085
Description
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Mailing List http://www.openwall.com/lists/oss-security/2020/09/16/6
Mailing List https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg00733.html
Exploit https://bugs.launchpad.net/qemu/+bug/1892960
Third Party Advisory https://security.netapp.com/advisory/ntap-20201009-0005/
Mailing List https://lists.debian.org/debian-lts-announce/2020/11/msg00047.html
Mailing List http://www.openwall.com/lists/oss-security/2021/03/09/1

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:qemu:qemu:5.0.0:-:*:*:*:*:*:* qemu == None == 5.0.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status