CVE-2018-7858Out-of-bounds Read in Qemu

CWE-125Out-of-bounds Read11 documents8 sources
Severity
5.5MEDIUMNVD
OSV10.0
EPSS
0.1%
top 82.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12
Latest updateMay 13

Description

Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

Debianqemu/qemu< 1:2.12~rc3+dfsg-1+3
Ubuntuqemu/qemu< 2.0.0+dfsg-2ubuntu1.41+2
NVDqemu/qemu2.11.2
NVDopensuse/leap42.3

Also affects: Ubuntu Linux 14.04, 16.04, 18.04, 18.10, Enterprise Linux 7.6, 7.5

Patches

🔴Vulnerability Details

4
GHSA
GHSA-f62g-jrwm-hq59: Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of serv2022-05-13
OSV
qemu vulnerabilities2018-05-16
OSV
CVE-2018-7858: Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of serv2018-03-12
CVEList
CVE-2018-7858: Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of serv2018-03-12

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2018-05-16
Red Hat
QEMU: cirrus: OOB access when updating VGA display2018-03-08
Debian
CVE-2018-7858: qemu - Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator sup...2018

💬Community

3
Bugzilla
CVE-2018-7858 QEMU: cirrus: OOB access when updating VGA display2018-03-08
Bugzilla
CVE-2018-7858 Qemu: cirrus: OOB access when updating VGA display [fedora-all]2018-03-08
Bugzilla
CVE-2018-7858 xen: QEMU: cirrus: OOB access when updating VGA display [fedora-all]2018-03-08
CVE-2018-7858 — Out-of-bounds Read in Qemu | cvebase