CVE-2018-18849Out-of-bounds Read in Qemu

Severity
5.5MEDIUMNVD
OSV6.5
EPSS
0.0%
top 85.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 14

Description

In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

debiandebian/qemu< qemu 1:3.1+dfsg-1 (bookworm)
Debianqemu/qemu< 1:3.1+dfsg-1+3
Ubuntuqemu/qemu< 2.0.0+dfsg-2ubuntu1.44+2
NVDqemu/qemu3.0.0
NVDopensuse/leap15.0, 42.3+1

Also affects: Fedora 29, Ubuntu Linux 14.04, 16.04, 18.04, 18.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-q3gm-vp97-w99p: In Qemu 32022-05-14
OSV
CVE-2018-18849: In Qemu 32019-03-21
OSV
qemu vulnerabilities2018-11-26

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2018-11-26
Red Hat
QEMU: lsi53c895a: OOB msg buffer access leads to DoS2018-10-25
Debian
CVE-2018-18849: qemu - In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access ...2018

💬Community

3
Bugzilla
CVE-2018-18849 qemu: lsi53c895a: OOB msg buffer access leads to DoS [fedora-all]2018-11-01
Bugzilla
CVE-2018-18849 QEMU: lsi53c895a: OOB msg buffer access leads to DoS2018-11-01
Bugzilla
CVE-2018-18849 xen: QEMU: lsi53c895a: OOB msg buffer access leads to DoS [fedora-all]2018-11-01