CVE-2018-19665Integer Overflow or Wraparound in Qemu

Severity
5.7MEDIUMNVD
EPSS
0.2%
top 57.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateMay 13

Description

The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.1 | Impact: 3.6

Affected Packages7 packages

debiandebian/qemu< qemu 1:3.1+dfsg-2 (bookworm)
Debianqemu/qemu< 1:3.1+dfsg-2+3
NVDqemu/qemu3.0.1+1
NVDopensuse/leap42.3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5qrx-9vpc-57pm: The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption2022-05-13
OSV
CVE-2018-19665: The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption2018-12-06

📋Vendor Advisories

3
Microsoft
The Bluetooth subsystem in QEMU mishandles negative values for length variables leading to memory corruption.2018-12-11
Red Hat
Qemu: bt: Integer overflow in Bluetooth routines allows memory corruption2018-10-18
Debian
CVE-2018-19665: qemu - The Bluetooth subsystem in QEMU mishandles negative values for length variables,...2018

💬Community

2
Bugzilla
CVE-2018-19665 qemu: bt: Integer overflow in Bluetooth routines allows memory corruption [fedora-all]2018-10-18
Bugzilla
CVE-2018-19665 Qemu: bt: Integer overflow in Bluetooth routines allows memory corruption2018-07-24