Bug 1883178 (CVE-2020-25742) - CVE-2020-25742 QEMU: scsi: lsi: null pointer dereference during memory move
Summary: CVE-2020-25742 QEMU: scsi: lsi: null pointer dereference during memory move
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2020-25742
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1883180 1883181 1910671
Blocks: 1850259
TreeView+ depends on / blocked
 
Reported: 2020-09-28 10:42 UTC by Prasad Pandit
Modified: 2023-07-14 16:00 UTC (History)
27 users (show)

Fixed In Version: QEMU 5.1.1
Doc Type: ---
Doc Text:
A NULL pointer dereference flaw was found in the LSI53C895A SCSI Host Bus Adapter emulator of QEMU. This flaw occurs while processing 'Memory Move' instructions to move data between DMA memory and I/O address space via lsi_memcpy(). This flaw allows a guest user or process to crash the QEMU process, resulting in a denial of service.
Clone Of:
Environment:
Last Closed: 2020-09-28 14:41:02 UTC
Embargoed:


Attachments (Terms of Use)
Samsung ManyManuals (1.53 KB, text/plain)
2023-06-30 12:34 UTC, elizabeth55
no flags Details

Description Prasad Pandit 2020-09-28 10:42:56 UTC
A null pointer dereference issue was found in the LSI53C895A SCSI Host Bus Adapter emulator of QEMU. It could occur while performing processing 'Memory Move' instructions to move data beteween dma memory and i/o address space via lsi_memcpy(). A guest user/process may use this flaw to crash the QEMU process resulting in DoS scenario.

Upstream patch(proposed):
--------------------------
  -> https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg05294.html

Comment 1 Prasad Pandit 2020-09-28 10:43:06 UTC
Acknowledgments:

Name: Sergej Schumilo (Ruhr-University Bochum), Cornelius Aschermann (Ruhr-University Bochum), Simon Wrner (Ruhr-University Bochum)

Comment 3 Prasad Pandit 2020-09-28 10:43:57 UTC
Created qemu tracking bugs for this issue:

Affects: fedora-all [bug 1883180]


Created xen tracking bugs for this issue:

Affects: fedora-all [bug 1883181]

Comment 4 Product Security DevOps Team 2020-09-28 14:41:02 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-25742

Comment 7 elizabeth55 2023-06-30 12:34:33 UTC
Created attachment 1973398 [details]
Samsung ManyManuals

Samsung is a prominent multinational conglomerate known for its diverse range of products and services. With its headquarters in South Korea, the company has established itself as a global leader in various industries.

Samsung operates in numerous sectors, including electronics, technology, finance, shipbuilding, construction, and more see here https://samsung.manymanuals.com/ . However, it is particularly renowned for its achievements in the consumer electronics market. The company produces an extensive array of devices such as smartphones, televisions, home appliances, computers, and audio equipment.

Comment 8 momser 2023-07-14 16:00:09 UTC
The List of LSI product devices comprises a comprehensive collection of 85 user manuals and guides, each corresponding to a specific model within 17 different types of devices. This extensive compilation caters to a diverse range of products offered by LSI, ensuring that customers have access to detailed instructions and information for seamless usage. Whether it's computers, peripherals, or other electronic equipment, the user manuals provide valuable insights into setup, troubleshooting, and optimizing the performance of LSI devices. With 85 models covered across 17 device types, LSI demonstrates their commitment to empowering users with the necessary resources to make the most of their products right at https://lsi.manymanuals.com/ .


Note You need to log in before you can comment on or make changes to this bug.