CVE-2020-13765
NixOS vulnerability analysis and mitigation

Overview

An out-of-bounds write access vulnerability was discovered in QEMU versions 4.0 and 4.1.0. The flaw exists in the rom_copy() function in hw/core/loader.c, which does not properly validate the relationship between two addresses when loading ROM contents at boot time (MITRE CVE, Red Hat CVE).

Technical details

The vulnerability occurs in the rom_copy() routine while loading the contents of a 32-bit -kernel image into memory. The code calculates a destination address without properly validating that rom->addr is greater than addr, which could result in a negative offset and cause memcpy() to write to an invalid memory location (OSS Security, QEMU Commit).

Impact

When successfully exploited, this vulnerability could allow attackers to load contents at arbitrary memory locations, potentially leading to code execution with the privileges of the QEMU process. The vulnerability has been assigned a CVSS score of 7.8 (HIGH) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NetApp Security).

Exploitability

The vulnerability can be exploited by running an untrusted kernel image, which may load contents at arbitrary memory locations. This could potentially lead to code execution with QEMU process privileges (Ubuntu Security).

Mitigation and workarounds

The vulnerability has been fixed in various distributions through security updates. Ubuntu has released patches for versions 16.04 LTS (1:2.5+dfsg-5ubuntu10.45), 18.04 LTS (1:2.11+dfsg-1ubuntu7.31), and 20.04 (1:4.2-3ubuntu6.4). Debian has also released fixes for Jessie (1:2.1+dfsg-12+deb8u15) and Stretch (1:2.8+dfsg-6+deb9u10) (Debian LTS, Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management