Multiple QEMU Vulnerabilities Affecting Ubuntu Systems

Multiple QEMU Vulnerabilities Affecting Ubuntu Systems

First seen 9 Jun 2026, 20:20 UTC UbuntuLinuxsecurity 87% similarity 57.8

Article Content

Browse articles
ThreatCluster

On June 9, 2026, Ubuntu announced several vulnerabilities in QEMU affecting versions 14.04 LTS to 20.04 LTS. The vulnerabilities include denial of service risks and potential arbitrary code execution due to improper handling of iSCSI responses (CVE-2020-1711) and memory operations (CVE-2020-11947). The issues primarily affect Ubuntu 14.04 LTS, with additional impacts on 16.04 LTS, 18.04 LTS, and 20.04 LTS. Attackers could exploit these vulnerabilities remotely or locally, leading to crashes and information exposure. The recommended action is to update to the latest package versions available through Ubuntu Pro. The vulnerabilities were discovered by multiple researchers, including Felipe Franciosi and Ziming Zhang.

Key Points: • QEMU vulnerabilities affect Ubuntu versions 14.04 to 20.04 LTS. • Denial of service and arbitrary code execution risks are present. • Immediate updates are recommended for affected systems.

ThreatCluster AI

Timeline

2020-02-11
CVE-2020-1711 published
Vulnerability in iSCSI block driver allows remote attackers to cause denial of service or execute code.
Ubuntu
2020-07-02
CVE-2020-15469 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-07-21
CVE-2020-15859 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-07-28
CVE-2020-15863 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-08-31
CVE-2020-12829 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-09-25
CVE-2020-25625 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-09-25
CVE-2020-25084 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-11-06
CVE-2020-27617 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-11-30
CVE-2020-25624 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-12-02
CVE-2020-25723 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →