CVE-2018-11806Out-of-bounds Write in Qemu

Severity
8.2HIGHNVD
EPSS
0.1%
top 82.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 13

Description

m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 1.5 | Impact: 6.0

Affected Packages7 packages

Debianqemu/qemu< 1:3.1+dfsg-1+3
NVDqemu/qemu2.12.1
NVDredhat/openstack5 versions+4

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10, Enterprise Linux 7.5, 7.6, 7.7

Patches

🔴Vulnerability Details

4
GHSA
GHSA-2vg8-mhwg-wq3f: m_cat in slirp/mbuf2022-05-13
OSV
qemu vulnerabilities2018-11-26
OSV
CVE-2018-11806: m_cat in slirp/mbuf2018-06-13
CVEList
CVE-2018-11806: m_cat in slirp/mbuf2018-06-13

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2018-11-26
Red Hat
QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams2018-06-05
Debian
CVE-2018-11806: qemu - m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming frag...2018

💬Community

2
Bugzilla
CVE-2018-11806 QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams2018-06-05
Bugzilla
CVE-2018-11806 QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams [fedora-all]2018-06-05
CVE-2018-11806 — Out-of-bounds Write in Qemu | cvebase