CVE-2020-15859

medium
Published 2021-11-09 Β· Modified 2021-11-09
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description QEMU: net: e1000e: use-after-free while sending packets Red Hat statement In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP qemu-kvm-rhev package. CVSS v3: 3.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L) Errata / fixed releases…

Description

QEMU: net: e1000e: use-after-free while sending packets

Red Hat statement

In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP qemu-kvm-rhev package.

CVSS v3: 3.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8virt-devel:rhel-8050020211001230723.b4937e53RHSA-2021:41912021-11-09T00:00:00Z
Red Hat Enterprise Linux 8virt:rhel-8050020211001230723.b4937e53RHSA-2021:41912021-11-09T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 7qemu-kvm-rhevWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmAffected
Red Hat Enterprise Linux 9qemu-kvmNot affected
Red Hat OpenStack Platform 10 (Newton)qemu-kvm-rhevWill not fix
Red Hat OpenStack Platform 13 (Queens)qemu-kvm-rhevWill not fix

Apply commands

bash fix
Apply RHSA-2021:4191 for Red Hat Enterprise Linux 8
yum update -y virt-devel:rhel
# or:
dnf upgrade -y virt-devel:rhel

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 5Not affected
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux 8 Advanced VirtualizationAffected
redhatRed Hat Enterprise Linux 9Not affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1:5.2+dfsg-1
sid Fixed 1:5.2+dfsg-1
forky Fixed 1:5.2+dfsg-1
bullseye Fixed 1:5.2+dfsg-1
bookworm Fixed 1:5.2+dfsg-1
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed β€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.