
Cloud Vulnerability DB
A community-led vulnerabilities database
An out-of-bounds write access vulnerability was discovered in QEMU versions 4.0 and 4.1.0. The flaw exists in the rom_copy() function in hw/core/loader.c, which does not properly validate the relationship between two addresses when loading ROM contents at boot time (MITRE CVE, Red Hat CVE).
The vulnerability occurs in the rom_copy() routine while loading the contents of a 32-bit -kernel image into memory. The code calculates a destination address without properly validating that rom->addr is greater than addr, which could result in a negative offset and cause memcpy() to write to an invalid memory location (OSS Security, QEMU Commit).
When successfully exploited, this vulnerability could allow attackers to load contents at arbitrary memory locations, potentially leading to code execution with the privileges of the QEMU process. The vulnerability has been assigned a CVSS score of 7.8 (HIGH) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NetApp Security).
The vulnerability can be exploited by running an untrusted kernel image, which may load contents at arbitrary memory locations. This could potentially lead to code execution with QEMU process privileges (Ubuntu Security).
The vulnerability has been fixed in various distributions through security updates. Ubuntu has released patches for versions 16.04 LTS (1:2.5+dfsg-5ubuntu10.45), 18.04 LTS (1:2.11+dfsg-1ubuntu7.31), and 20.04 (1:4.2-3ubuntu6.4). Debian has also released fixes for Jessie (1:2.1+dfsg-12+deb8u15) and Stretch (1:2.8+dfsg-6+deb9u10) (Debian LTS, Ubuntu Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."