cbcvebase.
CVE-2018-7858
published 2018-03-12

CVE-2018-7858: Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.

Affected

24 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianqemu< qemu 1:2.12~rc3+dfsg-1 (bookworm)qemu 1:2.12~rc3+dfsg-1 (bookworm)
opensuseleap
qemuqemu<= 2.11.2
qemuqemu>= 0 < 1:2.12~rc3+dfsg-11:2.12~rc3+dfsg-1
qemuqemu>= 0 < 1:2.12~rc3+dfsg-11:2.12~rc3+dfsg-1
qemuqemu>= 0 < 1:2.12~rc3+dfsg-11:2.12~rc3+dfsg-1
qemuqemu>= 0 < 1:2.12~rc3+dfsg-11:2.12~rc3+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.412.0.0+dfsg-2ubuntu1.41
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.281:2.5+dfsg-5ubuntu10.28
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.11:2.11+dfsg-1ubuntu7.1
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv10.0CRITICAL