Back to search
CVE-2020-15859
Published: Jul 21, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugs.launchpad.net/qemu/+bug/1886362
x_refsource_MISC
[oss-security] 20200721 CVE-2020-15859 QEMU: net: e1000e: use-after-free while sending packets
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20210218 [SECURITY] [DLA 2560-1] qemu security update
mailing-list
x_refsource_MLIST
GLSA-202208-27
vendor-advisory
x_refsource_GENTOO
[debian-lts-announce] 20220905 [SECURITY] [DLA 3099-1] qemu security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now