Bug 1883178 (CVE-2020-25742)
Summary: | CVE-2020-25742 QEMU: scsi: lsi: null pointer dereference during memory move | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Prasad Pandit <ppandit> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED NOTABUG | QA Contact: | |||||
Severity: | low | Docs Contact: | |||||
Priority: | low | ||||||
Version: | unspecified | CC: | ailan, berrange, bettyvilliams, cfergeau, drjones, imammedo, itamar, jen, jferlan, jforbes, jmaloy, knoel, m.a.young, mkenneth, momontovsergei, mrezanin, mst, ondrejj, pbonzini, philmd, ribarry, rjones, robinlee.sysu, virt-maint, virt-maint, vkuznets, xen-maint | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | QEMU 5.1.1 | Doc Type: | --- | ||||
Doc Text: |
A NULL pointer dereference flaw was found in the LSI53C895A SCSI Host Bus Adapter emulator of QEMU. This flaw occurs while processing 'Memory Move' instructions to move data between DMA memory and I/O address space via lsi_memcpy(). This flaw allows a guest user or process to crash the QEMU process, resulting in a denial of service.
|
Story Points: | --- | ||||
Clone Of: | Environment: | ||||||
Last Closed: | 2020-09-28 14:41:02 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 1883180, 1883181, 1910671 | ||||||
Bug Blocks: | 1850259 | ||||||
Attachments: |
|
Description
Prasad Pandit
2020-09-28 10:42:56 UTC
Acknowledgments: Name: Sergej Schumilo (Ruhr-University Bochum), Cornelius Aschermann (Ruhr-University Bochum), Simon Wrner (Ruhr-University Bochum) External References: https://www.openwall.com/lists/oss-security/2020/09/29/1 https://ruhr-uni-bochum.sciebo.de/s/NNWP2GfwzYKeKwE?path=%2Flsi_nullptr1 https://www.manualslib.com/manual/1407578/Lsi-Lsi53c895a.html?page=254#manual Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1883180] Created xen tracking bugs for this issue: Affects: fedora-all [bug 1883181] This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-25742 Created attachment 1973398 [details] Samsung ManyManuals Samsung is a prominent multinational conglomerate known for its diverse range of products and services. With its headquarters in South Korea, the company has established itself as a global leader in various industries. Samsung operates in numerous sectors, including electronics, technology, finance, shipbuilding, construction, and more see here https://samsung.manymanuals.com/ . However, it is particularly renowned for its achievements in the consumer electronics market. The company produces an extensive array of devices such as smartphones, televisions, home appliances, computers, and audio equipment. The List of LSI product devices comprises a comprehensive collection of 85 user manuals and guides, each corresponding to a specific model within 17 different types of devices. This extensive compilation caters to a diverse range of products offered by LSI, ensuring that customers have access to detailed instructions and information for seamless usage. Whether it's computers, peripherals, or other electronic equipment, the user manuals provide valuable insights into setup, troubleshooting, and optimizing the performance of LSI devices. With 85 models covered across 17 device types, LSI demonstrates their commitment to empowering users with the necessary resources to make the most of their products right at https://lsi.manymanuals.com/ . |