CVE-2018-20815
published 2019-05-31CVE-2018-20815: In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.
PriorityP348critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.43%
90.3th percentile
In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:3.1+dfsg-7 (bookworm) | qemu 1:3.1+dfsg-7 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:3.1+dfsg-7 | 1:3.1+dfsg-7 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-7 | 1:3.1+dfsg-7 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-7 | 1:3.1+dfsg-7 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-7 | 1:3.1+dfsg-7 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.46 | 2.0.0+dfsg-2ubuntu1.46 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.38 | 1:2.5+dfsg-5ubuntu10.38 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.13 | 1:2.11+dfsg-1ubuntu7.13 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4g35-fx39-gwjh: In QEMU 3
ghsa_unreviewed·2022-05-24
CVE-2018-20815 [CRITICAL] CWE-119 GHSA-4g35-fx39-gwjh: In QEMU 3
In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.
OSV
CVE-2018-20815: In QEMU 3
osv·2019-05-31·CVSS 9.8
CVE-2018-20815 [CRITICAL] CVE-2018-20815: In QEMU 3
In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.
OSV
qemu update
osv·2019-05-14·CVSS 5.6
[MEDIUM] qemu update
qemu update
Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan
Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa
Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos,
Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss
discovered that memory previously stored in microarchitectural fill buffers
of an Intel CPU core may be exposed to a malicious process that is
executing on the same CPU core. A local attacker could use this to expose
sensitive information. (CVE-2018-12130)
Brandon Falk, Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Stephan
van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh
Razavi, Herbert Bos, and Cristiano Giuffrida discovered that memory
previously stored in microarch
Ubuntu
QEMU update
vendor_ubuntu·2019-05-14·CVSS 5.6
CVE-2018-12126 [MEDIUM] QEMU update
Title: QEMU update
Summary: Several issues were addressed in QEMU.
Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan
Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa
Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos,
Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss
discovered that memory previously stored in microarchitectural fill buffers
of an Intel CPU core may be exposed to a malicious process that is
executing on the same CPU core. A local attacker could use this to expose
sensitive information. (CVE-2018-12130)
Brandon Falk, Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Stephan
van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh
Razavi, Herbert Bos, and Cristiano Giuffri
Red Hat
QEMU: device_tree: heap buffer overflow while loading device tree blob
vendor_redhat·2018-12-14·CVSS 9.8
CVE-2018-20815 [CRITICAL] CWE-122 QEMU: device_tree: heap buffer overflow while loading device tree blob
QEMU: device_tree: heap buffer overflow while loading device tree blob
In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.
A heap buffer overflow issue was found in the load_device_tree() function of QEMU, which is invoked to load a device tree blob at boot time. It occurs due to device tree size manipulation before buffer allocation, which could overflow a signed int type. A user/process could use this flaw to potentially execute arbitrary code on a host system with privileges of the QEMU process.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Lin
Debian
CVE-2018-20815: qemu - In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image...
vendor_debian·2018·CVSS 9.8
CVE-2018-20815 [CRITICAL] CVE-2018-20815: qemu - In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image...
In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-7)
bullseye: resolved (fixed in 1:3.1+dfsg-7)
forky: resolved (fixed in 1:3.1+dfsg-7)
sid: resolved (fixed in 1:3.1+dfsg-7)
trixie: resolved (fixed in 1:3.1+dfsg-7)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20815 qemu: device_tree: heap buffer overflow while loading device tree blob [fedora-all]
bugzilla·2019-03-27·CVSS 9.8
CVE-2018-20815 [CRITICAL] CVE-2018-20815 qemu: device_tree: heap buffer overflow while loading device tree blob [fedora-all]
CVE-2018-20815 qemu: device_tree: heap buffer overflow while loading device tree blob [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2018-20815 QEMU: device_tree: heap buffer overflow while loading device tree blob
bugzilla·2019-03-27·CVSS 9.8
CVE-2018-20815 [CRITICAL] CVE-2018-20815 QEMU: device_tree: heap buffer overflow while loading device tree blob
CVE-2018-20815 QEMU: device_tree: heap buffer overflow while loading device tree blob
A heap buffer overflow issue was found in the load_device_tree() function
of QEMU, which is invoked to load device tree blob at boot time.
It occurs due to device tree size manipulation before buffer allocation,
which could overflow a signed int type.
A user/process could use this flaw to potentially execute arbitrary
code on a host system with privileges of the QEMU process.
Upstream patch:
-> https://git.qemu.org/?p=qemu.git;a=commitdiff;h=da885fe1ee8b4589047484bd7fa05a4905b52b17
-> https://git.qemu.org/?p=qemu.git;a=commitdiff;h=065e6298a75164b4347682b63381dbe752c2b156
Reference:
-> https://www.openwall.com/lists/oss-security/2019/03/27/1
Discussion:
Created qemu tracking bugs for this issue:
Af
Bugzilla
CVE-2018-20815 xen: QEMU: device_tree: heap buffer overflow while loading device tree blob [fedora-all]
bugzilla·2019-03-27·CVSS 9.8
CVE-2018-20815 [CRITICAL] CVE-2018-20815 xen: QEMU: device_tree: heap buffer overflow while loading device tree blob [fedora-all]
CVE-2018-20815 xen: QEMU: device_tree: heap buffer overflow while loading device tree blob [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
https://access.redhat.com/errata/RHSA-2019:1667https://access.redhat.com/errata/RHSA-2019:1723https://access.redhat.com/errata/RHSA-2019:1743https://access.redhat.com/errata/RHSA-2019:1881https://access.redhat.com/errata/RHSA-2019:1968https://access.redhat.com/errata/RHSA-2019:2507https://access.redhat.com/errata/RHSA-2019:2553https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=da885fe1ee8b4589047484bd7fa05a4905b52b17https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BOE3PVFPMWMXV3DGP2R3XIHAF2ZQU3FS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVDHJB2QKXNDU7OFXIHIL5O5VN5QCSZL/https://seclists.org/bugtraq/2019/Aug/41https://www.debian.org/security/2019/dsa-4506https://access.redhat.com/errata/RHSA-2019:1667https://access.redhat.com/errata/RHSA-2019:1723https://access.redhat.com/errata/RHSA-2019:1743https://access.redhat.com/errata/RHSA-2019:1881https://access.redhat.com/errata/RHSA-2019:1968https://access.redhat.com/errata/RHSA-2019:2507https://access.redhat.com/errata/RHSA-2019:2553https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=da885fe1ee8b4589047484bd7fa05a4905b52b17https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BOE3PVFPMWMXV3DGP2R3XIHAF2ZQU3FS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVDHJB2QKXNDU7OFXIHIL5O5VN5QCSZL/https://seclists.org/bugtraq/2019/Aug/41https://www.debian.org/security/2019/dsa-4506
2019-05-31
Published