CVE-2016-4020

NameCVE-2016-4020
DescriptionThe patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1599-1, DLA-573-1, DLA-574-1
NVD severitylow
Debian Bugs821062

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qemu (PTS)stretch1:2.8+dfsg-6+deb9u9fixed
stretch (security)1:2.8+dfsg-6+deb9u14fixed
buster, buster (security)1:3.1+dfsg-8+deb10u8fixed
bullseye, sid1:5.2+dfsg-11fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
qemusourcewheezy1.1.2+dfsg-6+deb7u14DLA-573-1
qemusourcejessie1:2.1+dfsg-12+deb8u8DLA-1599-1
qemusource(unstable)1:2.6+dfsg-2821062
qemu-kvmsourcewheezy1.1.2+dfsg-6+deb7u14DLA-574-1
qemu-kvmsource(unstable)(unfixed)

Notes

https://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01118.html
https://bugzilla.redhat.com/show_bug.cgi?id=1313686
https://www.openwall.com/lists/oss-security/2016/04/13/6

Search for package or bug name: Reporting problems