« List of all CVEs

CVE-2020-13361

Published: 5/28/2020 Last updated: 8/4/2024 Reserved: 5/21/2020

In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (2)

conf-qemu-img nbd-tool

Products affected (2)

Product Vendor Version
n/a n/a < b3dfa878257a7e98830b3009ca5831a01d8f85fc
n/a n/a All versions < V3.10

References (40)