CVE-2020-11869: Qemu
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
Affected products
- Qemu Qemu: from 4.0.1, up to and including 4.2.0
Published 2020-04-27. Last modified 2026-06-17.