QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.html
http://www.openwall.com/lists/oss-security/2020/03/05/1
https://git.qemu.org/?p=qemu.git;a=commit;h=6bf21f3d83e95bcc4ba35a7a07cc6655e8b010b0
https://lists.debian.org/debian-lts-announce/2020/07/msg00020.html
Source: MITRE
Published: 2020-03-05
Updated: 2020-07-26
Type: CWE-401
Base Score: 2.7
Vector: AV:A/AC:L/Au:S/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 5.1
Severity: LOW
Base Score: 3.5
Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Impact Score: 1.4
Exploitability Score: 2.1
Severity: LOW