
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-12829 is a vulnerability discovered in QEMU's SM501 graphics driver, identified by security researcher Ziming Zhang. The vulnerability was disclosed in February 2020 and affects the COPY_AREA macro in the sm501_2d_engine_write() callback. This flaw occurs due to an integer overflow when handling MMIO write operations (NVD, Bugzilla).
The vulnerability stems from an integer overflow condition in the COPY_AREA macro within the Sm501_2d_operation() function in hw/display/sm501.c. The overflow occurs when the 'rtl' parameter is set to 1, and either 'src_y' or 'src_x' is less than 'operation_height'. This can lead to out-of-bounds read and write operations (Bugzilla). The vulnerability has been assigned a CVSS 3.0 score of 8.7 with High impact ratings (ManageEngine).
The vulnerability can allow an attacker inside a guest system to cause QEMU to crash, resulting in a denial of service. Additionally, under certain conditions, it may potentially allow the execution of arbitrary code (Ubuntu Security).
The vulnerability requires an attacker to have access to the guest system to exploit the flaw. The attack vector is local, requiring low attack complexity and low privileges, but with potential for high impact (ManageEngine).
The vulnerability has been patched in various distributions. Ubuntu has released updates for versions 20.04 LTS, 18.04 ESM, and 16.04 ESM. Debian has addressed this in version 1:3.1+dfsg-8+deb10u8. After applying the updates, all QEMU virtual machines need to be restarted to implement the security fixes (Ubuntu Security, Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."