cbcvebase.
CVE-2018-19489
published 2018-12-13

CVE-2018-19489: v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.

PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.40%
32.6th percentile
v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.

Affected

18 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:3.1+dfsg-1 (bookworm)qemu 1:3.1+dfsg-1 (bookworm)
fedoraprojectfedora
opensuseleap
qemuqemu<= 3.0.0
qemuqemu
qemuqemu>= 0 < 1:3.1+dfsg-11:3.1+dfsg-1
qemuqemu>= 0 < 1:3.1+dfsg-11:3.1+dfsg-1
qemuqemu>= 0 < 1:3.1+dfsg-11:3.1+dfsg-1
qemuqemu>= 0 < 1:3.1+dfsg-11:3.1+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.452.0.0+dfsg-2ubuntu1.45
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.361:2.5+dfsg-5ubuntu10.36
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.121:2.11+dfsg-1ubuntu7.12

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.