QEMU CVE-2020-13362 Out of Bounds Read Vulnerability

description-logoDescription

In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.

affected-products-logoAffected Applications

QEMU

CVE References

CVE-2020-13362