Bug 1883178 (CVE-2020-25742) - CVE-2020-25742 QEMU: scsi: lsi: null pointer dereference during memory move
Summary: CVE-2020-25742 QEMU: scsi: lsi: null pointer dereference during memory move
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2020-25742
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1883180 1883181 1910671
Blocks: 1850259
TreeView+ depends on / blocked
 
Reported: 2020-09-28 10:42 UTC by Prasad J Pandit
Modified: 2021-02-16 19:11 UTC (History)
25 users (show)

Fixed In Version: QEMU 5.1.1
Doc Type: ---
Doc Text:
A NULL pointer dereference flaw was found in the LSI53C895A SCSI Host Bus Adapter emulator of QEMU. This flaw occurs while processing 'Memory Move' instructions to move data between DMA memory and I/O address space via lsi_memcpy(). This flaw allows a guest user or process to crash the QEMU process, resulting in a denial of service.
Clone Of:
Environment:
Last Closed: 2020-09-28 14:41:02 UTC


Attachments (Terms of Use)

Description Prasad J Pandit 2020-09-28 10:42:56 UTC
A null pointer dereference issue was found in the LSI53C895A SCSI Host Bus Adapter emulator of QEMU. It could occur while performing processing 'Memory Move' instructions to move data beteween dma memory and i/o address space via lsi_memcpy(). A guest user/process may use this flaw to crash the QEMU process resulting in DoS scenario.

Upstream patch(proposed):
--------------------------
  -> https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg05294.html

Comment 1 Prasad J Pandit 2020-09-28 10:43:06 UTC
Acknowledgments:

Name: Sergej Schumilo (Ruhr-University Bochum), Cornelius Aschermann (Ruhr-University Bochum), Simon Wrner (Ruhr-University Bochum)

Comment 3 Prasad J Pandit 2020-09-28 10:43:57 UTC
Created qemu tracking bugs for this issue:

Affects: fedora-all [bug 1883180]


Created xen tracking bugs for this issue:

Affects: fedora-all [bug 1883181]

Comment 4 Product Security DevOps Team 2020-09-28 14:41:02 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-25742


Note You need to log in before you can comment on or make changes to this bug.