hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://lists.gnu.org/archive/html/qemu-devel/2020-03/msg08322.html | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2020/04/06/1 | third party advisory mailing list |
https://security.gentoo.org/glsa/202005-02 | vendor advisory |