CVE-2020-13765
—CVSS 3.1
5.6 medium
EPSS
2%p83
Published
()
Modified
Description
rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
In the news0 stories
No ingested article mentions this CVE yet.