Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Server SecurityKI-Deal-Maker: Vertrieb mit KI-Agenten automatisieren(25.09.2026 um 13:09 Uhr)
•
Server SecuritySales Enablement: Definition, Vorteile und Tools(25.09.2026 um 13:09 Uhr)
•
Server SecurityCorporate Identity(25.09.2026 um 14:09 Uhr)
••
Server SecurityDateirettung per grafischer Oberfläche(25.09.2026 um 07:00 Uhr)
•
Sicherheitslücken (CVE)Root für jedermann: Gefährliche Lücke in OxygenOS 16(25.09.2026 um 13:00 Uhr)
•
Server SecurityTux macht Feuer(26.09.2026 um 07:00 Uhr)
•
Server SecurityIm Test: Yubico YubiKey 5C Nano und NFC(28.09.2026 um 07:00 Uhr)
•
Sicherheitslücken (CVE)Nach KI-Ausbrüchen: OpenAI pausiert Training(28.09.2026 um 10:00 Uhr)
••
Server SecurityKI-Deal-Maker: Vertrieb mit KI-Agenten automatisieren(25.09.2026 um 13:09 Uhr)
•
Server SecuritySales Enablement: Definition, Vorteile und Tools(25.09.2026 um 13:09 Uhr)
•
Server SecurityCorporate Identity(25.09.2026 um 14:09 Uhr)
••
Server SecurityDateirettung per grafischer Oberfläche(25.09.2026 um 07:00 Uhr)
•
Sicherheitslücken (CVE)Root für jedermann: Gefährliche Lücke in OxygenOS 16(25.09.2026 um 13:00 Uhr)
•
Server SecurityTux macht Feuer(26.09.2026 um 07:00 Uhr)
•
Server SecurityIm Test: Yubico YubiKey 5C Nano und NFC(28.09.2026 um 07:00 Uhr)
•
Sicherheitslücken (CVE)Nach KI-Ausbrüchen: OpenAI pausiert Training(28.09.2026 um 10:00 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

USN-7094-1: QEMU vulnerabilities

It was discovered that QEMU incorrectly handled memory during certain VNC operations. A remote attacker could possibly use this issue to cause QEMU to consume resources, resulting in a denial of service. This issue only affected Ubuntu…

0
↗ Quelle (ubuntu.com)
Reagiere als Erste:r — dein Feedback zählt!
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2019-20382)

It was discovered that QEMU incorrectly handled certain memory copy
operations when loading ROM contents. If a user were tricked into running
an untrusted kernel image, a remote attacker could possibly use this issue
to run arbitrary code. This issue only affected Ubuntu 14.04 LTS.
(CVE-2020-13765)

Aviv Sasson discovered that QEMU incorrectly handled Slirp networking. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS. (CVE-2020-1983)

It was discovered that the SLiRP networking implementation of the QEMU
emulator did not properly manage memory under certain circumstances. An
attacker could use this to cause a heap-based buffer overflow or other out-
of-bounds access, which can lead to a denial of service (application crash)
or potential execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS. (CVE-2020-7039)

It was discovered that the SLiRP networking implementation of the QEMU
emulator misuses snprintf return values. An attacker could use this to
cause a denial of service (application crash) or potentially execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-8608)

It was discovered that QEMU SLiRP networking incorrectly handled certain
udp packets. An attacker inside a guest could possibly use this issue to
leak sensitive information from the host. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3592, CVE-2021-3594)

It was discovered that QEMU had a DMA reentrancy issue, leading to a
use-after-free vulnerability. An attacker could possibly use this issue
to cause a denial of service. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-3019)

It was discovered that QEMU had a flaw in Virtio PCI Bindings, leading
to a triggerable crash via vhost_net_stop. An attacker inside a guest
could possibly use this issue to cause a denial of service. This issue
only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2024-4693)

It was discovered that QEMU incorrectly handled memory in virtio-sound,
leading to a heap-based buffer overflow. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2024-7730)

2. Cyber Threat Intelligence & Forensik

IoC Intelligence (10 Indikatoren)
CVE-2019-20382CVE-2020-13765CVE-2020-1983CVE-2020-7039CVE-2020-8608CVE-2021-3592CVE-2021-3594CVE-2023-3019+2 weitere
CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle Timeline
CVE-2020-13765
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Noch kein offizieller Patch dokumentiert
Exploit Weaponization & Public PoC Radar
ELEVATED · Index 15/100
Exploit-DB
Kein EDB-Eintrag
Interaktion
Interaktion nötig
Authentifizierung
Erforderlich

3. Compliance, SLA & Vendor Adherence

Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

In herstellerseitiger Prüfung
Handlungsempfehlung für Administratoren

Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
  • Keine herstellerspezifischen Bulletins in der Primärquelle hinterlegt.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten USN-7094-1: QEMU vulnerabilities

Thematisch verwandte Begriffe: USN70941, QEMU, vulnerabilities · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-88808 | A vulnerability has been identified within Rancher Manager where the Fle…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag