USN-4725-1: QEMU vulnerabilities

Publication date

8 February 2021

Overview

Several security issues were fixed in QEMU.


Packages

  • qemu - Machine emulator and virtualizer

Details

It was discovered that QEMU incorrectly handled memory in iSCSI emulation.
An attacker inside the guest could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-11947)

Alexander Bulekov discovered that QEMU incorrectly handled Intel e1000e
emulation. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2020-15859)

Alexander Bulekov discovered that QEMU incorrectly handled memory region
cache. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS, and Ubuntu 20.10. (CVE-2020-27821)

Cheol-woo Myung discovered that QEMU incorrectly handled Intel...

It was discovered that QEMU incorrectly handled memory in iSCSI emulation.
An attacker inside the guest could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-11947)

Alexander Bulekov discovered that QEMU incorrectly handled Intel e1000e
emulation. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2020-15859)

Alexander Bulekov discovered that QEMU incorrectly handled memory region
cache. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS, and Ubuntu 20.10. (CVE-2020-27821)

Cheol-woo Myung discovered that QEMU incorrectly handled Intel e1000e
emulation. An attacker inside the guest could use this issue to cause a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, and Ubuntu 20.10. (CVE-2020-28916)

Wenxiang Qian discovered that QEMU incorrectly handled ATAPI emulation. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. (CVE-2020-29443)

It was discovered that QEMU incorrectly handled VirtFS directory sharing.
An attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. (CVE-2021-20181)


Update instructions

After a standard system update you need to restart all QEMU virtual machines to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
20.10 groovy qemu-system –  1:5.0-5ubuntu9.4
qemu-system-arm –  1:5.0-5ubuntu9.4
qemu-system-mips –  1:5.0-5ubuntu9.4
qemu-system-misc –  1:5.0-5ubuntu9.4
qemu-system-ppc –  1:5.0-5ubuntu9.4
qemu-system-s390x –  1:5.0-5ubuntu9.4
qemu-system-sparc –  1:5.0-5ubuntu9.4
qemu-system-x86 –  1:5.0-5ubuntu9.4
qemu-system-x86-microvm –  1:5.0-5ubuntu9.4
qemu-system-x86-xen –  1:5.0-5ubuntu9.4
20.04 focal qemu-system –  1:4.2-3ubuntu6.12
qemu-system-arm –  1:4.2-3ubuntu6.12
qemu-system-mips –  1:4.2-3ubuntu6.12
qemu-system-misc –  1:4.2-3ubuntu6.12
qemu-system-ppc –  1:4.2-3ubuntu6.12
qemu-system-s390x –  1:4.2-3ubuntu6.12
qemu-system-sparc –  1:4.2-3ubuntu6.12
qemu-system-x86 –  1:4.2-3ubuntu6.12
qemu-system-x86-microvm –  1:4.2-3ubuntu6.12
qemu-system-x86-xen –  1:4.2-3ubuntu6.12
18.04 bionic qemu-system –  1:2.11+dfsg-1ubuntu7.35
qemu-system-arm –  1:2.11+dfsg-1ubuntu7.35
qemu-system-mips –  1:2.11+dfsg-1ubuntu7.35
qemu-system-misc –  1:2.11+dfsg-1ubuntu7.35
qemu-system-ppc –  1:2.11+dfsg-1ubuntu7.35
qemu-system-s390x –  1:2.11+dfsg-1ubuntu7.35
qemu-system-sparc –  1:2.11+dfsg-1ubuntu7.35
qemu-system-x86 –  1:2.11+dfsg-1ubuntu7.35
16.04 xenial qemu-system –  1:2.5+dfsg-5ubuntu10.49
qemu-system-aarch64 –  1:2.5+dfsg-5ubuntu10.49
qemu-system-arm –  1:2.5+dfsg-5ubuntu10.49
qemu-system-mips –  1:2.5+dfsg-5ubuntu10.49
qemu-system-misc –  1:2.5+dfsg-5ubuntu10.49
qemu-system-ppc –  1:2.5+dfsg-5ubuntu10.49
qemu-system-s390x –  1:2.5+dfsg-5ubuntu10.49
qemu-system-sparc –  1:2.5+dfsg-5ubuntu10.49
qemu-system-x86 –  1:2.5+dfsg-5ubuntu10.49

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›