Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-12829
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-12829 is a vulnerability discovered in QEMU's SM501 graphics driver, identified by security researcher Ziming Zhang. The vulnerability was disclosed in February 2020 and affects the COPY_AREA macro in the sm501_2d_engine_write() callback. This flaw occurs due to an integer overflow when handling MMIO write operations (NVD, Bugzilla).

Technical details

The vulnerability stems from an integer overflow condition in the COPY_AREA macro within the Sm501_2d_operation() function in hw/display/sm501.c. The overflow occurs when the 'rtl' parameter is set to 1, and either 'src_y' or 'src_x' is less than 'operation_height'. This can lead to out-of-bounds read and write operations (Bugzilla). The vulnerability has been assigned a CVSS 3.0 score of 8.7 with High impact ratings (ManageEngine).

Impact

The vulnerability can allow an attacker inside a guest system to cause QEMU to crash, resulting in a denial of service. Additionally, under certain conditions, it may potentially allow the execution of arbitrary code (Ubuntu Security).

Exploitability

The vulnerability requires an attacker to have access to the guest system to exploit the flaw. The attack vector is local, requiring low attack complexity and low privileges, but with potential for high impact (ManageEngine).

Mitigation and workarounds

The vulnerability has been patched in various distributions. Ubuntu has released updates for versions 20.04 LTS, 18.04 ESM, and 16.04 ESM. Debian has addressed this in version 1:3.1+dfsg-8+deb10u8. After applying the updates, all QEMU virtual machines need to be restarted to implement the security fixes (Ubuntu Security, Debian Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-15-binutils-devel
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management