QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data’s address set to the e1000e’s MMIO address.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15859
Reference (s):
- https://bugs.launchpad.net/qemu/+bug/1886362
- https://lists.gnu.org/archive/html/qemu-devel/2020-07/msg05304.html
- MLIST:[debian-lts-announce] 20210218 [SECURITY] [DLA 2560-1] qemu security update
- URL: https://lists.debian.org/debian-lts-announce/2021/02/msg00024.html
- MLIST:[oss-security] 20200721 CVE-2020-15859 QEMU: net: e1000e: use-after-free while sending packets

