Hide Forgot
A null pointer dereference issue was found in the LSI53C895A SCSI Host Bus Adapter emulator of QEMU. It could occur while performing processing 'Memory Move' instructions to move data beteween dma memory and i/o address space via lsi_memcpy(). A guest user/process may use this flaw to crash the QEMU process resulting in DoS scenario. Upstream patch(proposed): -------------------------- -> https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg05294.html
Acknowledgments: Name: Sergej Schumilo (Ruhr-University Bochum), Cornelius Aschermann (Ruhr-University Bochum), Simon Wrner (Ruhr-University Bochum)
External References: https://www.openwall.com/lists/oss-security/2020/09/29/1 https://ruhr-uni-bochum.sciebo.de/s/NNWP2GfwzYKeKwE?path=%2Flsi_nullptr1 https://www.manualslib.com/manual/1407578/Lsi-Lsi53c895a.html?page=254#manual
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1883180] Created xen tracking bugs for this issue: Affects: fedora-all [bug 1883181]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-25742