CVE-2018-5748
published 2018-01-25CVE-2018-5748: qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
PriorityP433high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.17%
86.5th percentile
qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libvirt | < libvirt 4.1.0-1 (bookworm) | libvirt 4.1.0-1 (bookworm) |
| debian | libvirt | < libvirt 4.0.0-1 (bookworm) | libvirt 4.0.0-1 (bookworm) |
| libvirt | libvirt | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | libvirt | <= 4.1.0 | — |
| redhat | libvirt | >= 0 < 4.1.0-1 | 4.1.0-1 |
| redhat | libvirt | >= 0 < 4.0.0-1 | 4.0.0-1 |
| redhat | libvirt | >= 0 < 4.1.0-1 | 4.1.0-1 |
| redhat | libvirt | >= 0 < 4.0.0-1 | 4.0.0-1 |
| redhat | libvirt | >= 0 < 4.1.0-1 | 4.1.0-1 |
| redhat | libvirt | >= 0 < 4.0.0-1 | 4.0.0-1 |
| redhat | libvirt | >= 0 < 4.1.0-1 | 4.1.0-1 |
| redhat | libvirt | >= 0 < 4.0.0-1 | 4.0.0-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
vendor_redhat·2018-03-14·CVSS 7.5
CVE-2018-1064 [HIGH] CWE-400 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
An incomplete fix for CVE-2018-5748 that affects QEMU monitor leading to a resource exhaustion but now also triggered via QEMU guest agent.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 8) - Not affected
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2018-02-20·CVSS 9.8
CVE-2016-5008 [CRITICAL] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Vivian Zhang and Christoph Anton Mitterer discovered that libvirt
incorrectly disabled password authentication when the VNC password was set
to an empty string. A remote attacker could possibly use this issue to
bypass authentication, contrary to expectations. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-5008)
Daniel P. Berrange discovered that libvirt incorrectly handled validating
SSL/TLS certificates. A remote attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 17.10.
(CVE-2017-1000256)
Daniel P. Berrange and Peter Krempa discovered that libvirt incorrectly
handled large QEMU replies. An attacker could possibly use th
Red Hat
libvirt: Resource exhaustion via qemuMonitorIORead() method
vendor_redhat·2018-01-16·CVSS 7.5
CVE-2018-5748 [HIGH] CWE-400 libvirt: Resource exhaustion via qemuMonitorIORead() method
libvirt: Resource exhaustion via qemuMonitorIORead() method
qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2018-1064: libvirt - libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a res...
vendor_debian·2018·CVSS 7.5
CVE-2018-1064 [HIGH] CVE-2018-1064: libvirt - libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a res...
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
Scope: local
bookworm: resolved (fixed in 4.1.0-1)
bullseye: resolved (fixed in 4.1.0-1)
forky: resolved (fixed in 4.1.0-1)
sid: resolved (fixed in 4.1.0-1)
trixie: resolved (fixed in 4.1.0-1)
Debian
CVE-2018-5748: libvirt - qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (me...
vendor_debian·2018·CVSS 7.5
CVE-2018-5748 [HIGH] CVE-2018-5748: libvirt - qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (me...
qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
Scope: local
bookworm: resolved (fixed in 4.0.0-1)
bullseye: resolved (fixed in 4.0.0-1)
forky: resolved (fixed in 4.0.0-1)
sid: resolved (fixed in 4.0.0-1)
trixie: resolved (fixed in 4.0.0-1)
GHSA
GHSA-r8xf-5287-837j: libvirt version before 4
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2018-1064 [HIGH] CWE-400 GHSA-r8xf-5287-837j: libvirt version before 4
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
GHSA
GHSA-vgrm-6fx3-7frj: qemu/qemu_monitor
ghsa_unreviewed·2022-05-13
CVE-2018-5748 [HIGH] CWE-400 GHSA-vgrm-6fx3-7frj: qemu/qemu_monitor
qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
OSV
CVE-2018-1064: libvirt version before 4
osv·2018-03-28·CVSS 7.5
CVE-2018-1064 [HIGH] CVE-2018-1064: libvirt version before 4
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
OSV
libvirt vulnerabilities
osv·2018-02-20·CVSS 9.8
CVE-2016-5008 [CRITICAL] libvirt vulnerabilities
libvirt vulnerabilities
Vivian Zhang and Christoph Anton Mitterer discovered that libvirt
incorrectly disabled password authentication when the VNC password was set
to an empty string. A remote attacker could possibly use this issue to
bypass authentication, contrary to expectations. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-5008)
Daniel P. Berrange discovered that libvirt incorrectly handled validating
SSL/TLS certificates. A remote attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 17.10.
(CVE-2017-1000256)
Daniel P. Berrange and Peter Krempa discovered that libvirt incorrectly
handled large QEMU replies. An attacker could possibly use this issue to
cause libvirt to crash, resulting in a denial of ser
OSV
CVE-2018-5748: qemu/qemu_monitor
osv·2018-01-25·CVSS 7.5
CVE-2018-5748 [HIGH] CVE-2018-5748: qemu/qemu_monitor
qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1064 mingw-libvirt: libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent [fedora-all]
bugzilla·2018-03-22·CVSS 7.5
CVE-2018-1064 [HIGH] CVE-2018-1064 mingw-libvirt: libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent [fedora-all]
CVE-2018-1064 mingw-libvirt: libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2018-1064 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
bugzilla·2018-03-01·CVSS 7.5
CVE-2018-1064 [HIGH] CVE-2018-1064 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
CVE-2018-1064 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
An incomplete fix for CVE-2018-5748 that affects QEMU monitor leading to a resource exhaustion but now also triggered via QEMU guest agent.
Upstream patch:
https://libvirt.org/git/?p=libvirt.git;a=commit;h=fbf31e1a4cd19d6f6e33e0937a009775cd7d9513
Discussion:
Created mingw-libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1559517]
---
Acknowledgments:
Name: Daniel P. Berrange (Red Hat)
---
External References:
https://security.libvirt.org/2018/0004.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1396 https://access.redhat.com/errata/RHSA-2018:1396
---
This issue has been addressed in the following products:
Red Hat E
Bugzilla
CVE-2018-5748 Libvirt: resource exhaustion via qemuMonitorIORead() method [fedora-all]
bugzilla·2018-01-18·CVSS 7.5
CVE-2018-5748 [HIGH] CVE-2018-5748 Libvirt: resource exhaustion via qemuMonitorIORead() method [fedora-all]
CVE-2018-5748 Libvirt: resource exhaustion via qemuMonitorIORead() method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2018-5748 libvirt: Resource exhaustion via qemuMonitorIORead() method
bugzilla·2017-12-21·CVSS 7.5
CVE-2018-5748 [HIGH] CVE-2018-5748 libvirt: Resource exhaustion via qemuMonitorIORead() method
CVE-2018-5748 libvirt: Resource exhaustion via qemuMonitorIORead() method
A flaw was found in Qemu. A lack of restriction for the amount of data read by QEMU Monitor socket can lead to denial of service by exhaustion of memory resources.
References:
https://www.redhat.com/archives/libvir-list/2017-December/msg00749.html
Discussion:
Acknowledgments:
Name: Daniel P. Berrange (Red Hat), Peter Krempa (Red Hat)
---
Created libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1535785]
---
Although RHES-3 (RHGS) is shipped with libvirt, it does not use Qemu. As such, there is no qemu process running, and no vulnerable monitor socket created.
---
libvirt-3.7.0-4.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this
http://www.securityfocus.com/bid/102825https://access.redhat.com/errata/RHSA-2018:1396https://access.redhat.com/errata/RHSA-2018:1929https://lists.debian.org/debian-lts-announce/2018/03/msg00018.htmlhttps://www.debian.org/security/2018/dsa-4137https://www.redhat.com/archives/libvir-list/2018-January/msg00527.htmlhttp://www.securityfocus.com/bid/102825https://access.redhat.com/errata/RHSA-2018:1396https://access.redhat.com/errata/RHSA-2018:1929https://lists.debian.org/debian-lts-announce/2018/03/msg00018.htmlhttps://www.debian.org/security/2018/dsa-4137https://www.redhat.com/archives/libvir-list/2018-January/msg00527.html
2018-01-25
Published