Bug 1903064 (CVE-2020-28916) - CVE-2020-28916 QEMU: e1000e: infinite loop scenario in case of null packet descriptor
Summary: CVE-2020-28916 QEMU: e1000e: infinite loop scenario in case of null packet de...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2020-28916
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: CVE-2020-25707 (view as bug list)
Depends On: 1903066 1903069 1903070 1903071 1910661
Blocks: 1887771 1892339
TreeView+ depends on / blocked
 
Reported: 2020-12-01 09:06 UTC by Prasad J Pandit
Modified: 2022-04-17 21:04 UTC (History)
34 users (show)

Fixed In Version: QEMU 5.2.0
Doc Type: ---
Doc Text:
An infinite loop flaw was found in the e1000e device emulator in QEMU. This issue could occur while receiving packets via the e1000e_write_packet_to_guest() routine, if the receive(RX) descriptor has a NULL buffer address. This flaw allows a privileged guest user to cause a denial of service. The highest threat from this vulnerability is to system availability.
Clone Of:
Environment:
Last Closed: 2021-05-18 14:37:26 UTC


Attachments (Terms of Use)

Description Prasad J Pandit 2020-12-01 09:06:30 UTC
An infinite loop issue was found in the e1000e device emulator in QEMU. The issue could occur while receiving packets via e1000e_write_packet_to_guest() routine, if the receive(RX) descriptor has NULL buffer address. A privileged guest user may use this flaw to induce a DoS scenario in the host.

Upstream patch:
---------------
  -> https://lists.nongnu.org/archive/html/qemu-devel/2020-11/msg03185.html

Comment 1 Prasad J Pandit 2020-12-01 09:06:45 UTC
Acknowledgments:

Name: Cheol-woo Myung

Comment 2 Prasad J Pandit 2020-12-01 09:07:44 UTC
Created qemu tracking bugs for this issue:

Affects: fedora-all [bug 1903066]

Comment 5 Prasad J Pandit 2020-12-01 12:10:42 UTC
External References:

https://www.openwall.com/lists/oss-security/2020/12/01/2

Comment 6 Mauro Matteo Cascella 2020-12-14 14:11:30 UTC
*** Bug 1893895 has been marked as a duplicate of this bug. ***

Comment 8 Product Security DevOps Team 2021-05-18 14:37:26 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-28916

Comment 9 errata-xmlrpc 2021-05-18 14:51:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2021:1762 https://access.redhat.com/errata/RHSA-2021:1762


Note You need to log in before you can comment on or make changes to this bug.