
Cloud Vulnerability DB
A community-led vulnerabilities database
QEMU 4.2.0 contains a use-after-free vulnerability (CVE-2020-15859) in the hw/net/e1000e_core.c component, discovered in July 2020. The vulnerability occurs when a guest OS user triggers an e1000e packet with the data's address set to the e1000e's MMIO address (CVE-MITRE, DEBIAN-LTS).
The vulnerability is caused by a use-after-free condition in the e1000e network device emulation code. When processing network packets, if a guest sets the packet data address to the e1000e's MMIO (Memory-Mapped I/O) address, it triggers a re-entrant condition during DMA operations that leads to the use of already freed memory (LAUNCHPAD-BUG, OSS-SECURITY). The vulnerability has a CVSS v3.1 base score of 3.3 (Low) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L (UBUNTU-SEC).
The exploitation of this vulnerability could allow a guest user/process to crash the QEMU process on the host, resulting in a denial of service (DoS) scenario (OSS-SECURITY).
The vulnerability can be triggered by a guest OS user by manipulating the e1000e packet data address to point to the device's MMIO address. Proof-of-concept exploits have been documented in the bug report, demonstrating the ability to consistently trigger the use-after-free condition (LAUNCHPAD-BUG).
The issue has been fixed in various distributions through security updates. Debian 9 (Stretch) users should upgrade to version 1:2.8+dfsg-6+deb9u13, Debian 10 (Buster) users should upgrade to version 1:3.1+dfsg-8+deb10u9, and Ubuntu users should upgrade to their respective fixed versions (DEBIAN-LTS, DEBIAN-LTS-2). The fix involves using a bottom half handler to process descriptors when MMIO is performing complex operations, which prevents the re-entrancy issue (GNU-PATCH).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."