DescriptionHeap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.
Debian Bugs793811

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qemu (PTS)buster1:3.1+dfsg-8+deb10u8fixed
buster (security)1:3.1+dfsg-8+deb10u10fixed
bullseye (security), bullseye1:5.2+dfsg-11+deb11u2fixed
bookworm, sid1:7.2+dfsg-5fixed
xen (PTS)buster, buster (security)4.11.4+107-gef32c7afa2-1fixed
bullseye (security)4.14.5+94-ge49571868d-1fixed
bookworm, sid4.17.0+46-gaaf74a532c-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
qemusourcesqueeze(not affected)
qemusourcewheezy(not affected)
qemu-kvmsource(unstable)(not affected)
xensourcesqueeze(not affected)
xensourcewheezy(not affected)


[wheezy] - qemu <not-affected> (Vulnerable code not present, introduced in 1.3)
[squeeze] - qemu <not-affected> (Vulnerable code not present, introduced in 1.3)
- qemu-kvm <not-affected> (Vulnerable code not present, introduced in 1.3)
[wheezy] - xen <not-affected> (Vulnerable code not present, introduced in 4.2)
[squeeze] - xen <not-affected> (Vulnerable code not present, introduced in 4.2)
Xen switched to qemu-system in 4.4.0-1
qemu patches:;a=commit;h=d2ff85854512574e7209f295e87b0835d5b032c6;a=commit;h=cb72cba83021fa42719e73a5249c12096a4d1cfc;a=commit;h=03441c3a4a42beb25460dd11592539030337d0f8
Introduced by:;a=commitdiff;h=ce560dcf20c14194db5ef3b9fc1ea592d4e68109 (v1.3.0-rc0)

