CVE-2019-13164
published 2019-07-03CVE-2019-13164: qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.52%
40.9th percentile
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:4.1-1 (bookworm) | qemu 1:4.1-1 (bookworm) |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:4.1-1 | 1:4.1-1 |
| qemu | qemu | >= 0 < 1:4.1-1 | 1:4.1-1 |
| qemu | qemu | >= 0 < 1:4.1-1 | 1:4.1-1 |
| qemu | qemu | >= 0 < 1:4.1-1 | 1:4.1-1 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.42 | 1:2.5+dfsg-5ubuntu10.42 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.20 | 1:2.11+dfsg-1ubuntu7.20 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.47 | 2.0.0+dfsg-2ubuntu1.47 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2019-11-14·CVSS 3.8
CVE-2019-12068 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
USN-4191-2 fixed a vulnerability in QEMU. This update provides the
corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that the LSI SCSI adapter emulator implementation in QEMU
did not properly validate executed scripts. A local attacker could use this
to cause a denial of service. (CVE-2019-12068)
Sergej Schumilo, Cornelius Aschermann and Simon Wörner discovered that the
qxl paravirtual graphics driver implementation in QEMU contained a null
pointer dereference. A local attacker in a guest could use this to cause a
denial of service. (CVE-2019-12155)
Riccardo Schirone discovered that the QEMU bridge helper did not properly
validate network interface names. A local att
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2019-11-14·CVSS 3.8
CVE-2019-12068 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that the LSI SCSI adapter emulator implementation in QEMU
did not properly validate executed scripts. A local attacker could use this
to cause a denial of service. (CVE-2019-12068)
Sergej Schumilo, Cornelius Aschermann and Simon Wörner discovered that the
qxl paravirtual graphics driver implementation in QEMU contained a null
pointer dereference. A local attacker in a guest could use this to cause a
denial of service. (CVE-2019-12155)
Riccardo Schirone discovered that the QEMU bridge helper did not properly
validate network interface names. A local attacker could possibly use this
to bypass ACL restrictions. (CVE-2019-13164)
It was discovered that a heap-based buffer overflow existed in
Red Hat
Qemu: qemu-bridge-helper ACL can be bypassed when names are too long
vendor_redhat·2019-06-28·CVSS 7.8
CVE-2019-13164 [HIGH] CWE-284 Qemu: qemu-bridge-helper ACL can be bypassed when names are too long
Qemu: qemu-bridge-helper ACL can be bypassed when names are too long
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
Statement: Red Hat Virtualization Hypervisor is not affected by this vulnerability, as its bridge configuration can not take the required form.
Mitigation: This flaw can only be exploited if `/etc/qemu*/bridge.conf` contains a line containing `allow all` or at least one line with a bridge name of at least 15 characters.
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Fix deferred
Package: qemu-kvm-ma (Red Hat Enterprise Linux 7) - Fix deferred
Packag
Debian
CVE-2019-13164: qemu - qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interf...
vendor_debian·2019·CVSS 7.8
CVE-2019-13164 [HIGH] CVE-2019-13164: qemu - qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interf...
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
Scope: local
bookworm: resolved (fixed in 1:4.1-1)
bullseye: resolved (fixed in 1:4.1-1)
forky: resolved (fixed in 1:4.1-1)
sid: resolved (fixed in 1:4.1-1)
trixie: resolved (fixed in 1:4.1-1)
GHSA
GHSA-5ff7-wj9x-5xc5: qemu-bridge-helper
ghsa_unreviewed·2022-05-24
CVE-2019-13164 [HIGH] GHSA-5ff7-wj9x-5xc5: qemu-bridge-helper
qemu-bridge-helper.c in QEMU 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
OSV
qemu vulnerabilities
osv·2019-11-14·CVSS 3.8
CVE-2019-12068 [LOW] qemu vulnerabilities
qemu vulnerabilities
USN-4191-2 fixed a vulnerability in QEMU. This update provides the
corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that the LSI SCSI adapter emulator implementation in QEMU
did not properly validate executed scripts. A local attacker could use this
to cause a denial of service. (CVE-2019-12068)
Sergej Schumilo, Cornelius Aschermann and Simon Wörner discovered that the
qxl paravirtual graphics driver implementation in QEMU contained a null
pointer dereference. A local attacker in a guest could use this to cause a
denial of service. (CVE-2019-12155)
Riccardo Schirone discovered that the QEMU bridge helper did not properly
validate network interface names. A local attacker could possibly use this
to bypass ACL restrictions. (CV
OSV
qemu vulnerabilities
osv·2019-11-14·CVSS 3.8
CVE-2019-12068 [LOW] qemu vulnerabilities
qemu vulnerabilities
It was discovered that the LSI SCSI adapter emulator implementation in QEMU
did not properly validate executed scripts. A local attacker could use this
to cause a denial of service. (CVE-2019-12068)
Sergej Schumilo, Cornelius Aschermann and Simon Wörner discovered that the
qxl paravirtual graphics driver implementation in QEMU contained a null
pointer dereference. A local attacker in a guest could use this to cause a
denial of service. (CVE-2019-12155)
Riccardo Schirone discovered that the QEMU bridge helper did not properly
validate network interface names. A local attacker could possibly use this
to bypass ACL restrictions. (CVE-2019-13164)
It was discovered that a heap-based buffer overflow existed in the SLiRP
networking implementation of QEMU. A local attacker
OSV
CVE-2019-13164: qemu-bridge-helper
osv·2019-07-03·CVSS 7.8
CVE-2019-13164 [HIGH] CVE-2019-13164: qemu-bridge-helper
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
No detection rules found.
No public exploits indexed.
Bugzilla
qemu: long interface names in qemu-bridge-helper leading to ACL bypass
bugzilla·2019-07-15·CVSS 7.8
[HIGH] qemu: long interface names in qemu-bridge-helper leading to ACL bypass
qemu: long interface names in qemu-bridge-helper leading to ACL bypass
The network interface name in Linux is defined to be of size IFNAMSIZ(=16), including the terminating null('\0') byte. The same is applied to interface names read from 'bridge.conf' file to form ACL rules. If user supplied '--br=bridge' name is not restricted to the same length, it could lead to ACL bypass issue. Restrict interface name to IFNAMSIZ, including null byte.
Upstream Issue:
https://lists.gnu.org/archive/html/qemu-devel/2019-07/msg00245.html
Discussion:
Created qemu tracking bugs for this issue:
Affects: epel-7 [bug 1729960]
Affects: fedora-all [bug 1729959]
---
Hi
I think the CVE id ist a typo and it should be CVE-2019-13164? The later is already mentioned in https://www.openwall.com/lists/oss-secur
Bugzilla
CVE-2019-13164 qemu: qemu-bridge-helper ACL can be bypassed when names are too long [fedora-all]
bugzilla·2019-07-02·CVSS 7.8
CVE-2019-13164 [HIGH] CVE-2019-13164 qemu: qemu-bridge-helper ACL can be bypassed when names are too long [fedora-all]
CVE-2019-13164 qemu: qemu-bridge-helper ACL can be bypassed when names are too long [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2019-13164 Qemu: qemu-bridge-helper ACL can be bypassed when names are too long
bugzilla·2019-06-20·CVSS 7.8
CVE-2019-13164 [HIGH] CVE-2019-13164 Qemu: qemu-bridge-helper ACL can be bypassed when names are too long
CVE-2019-13164 Qemu: qemu-bridge-helper ACL can be bypassed when names are too long
It was discovered that the Access Control List (ACL) implemented by
qemu-bridge-helper program could be bypassed in particular cases when the bridge
interface names are as long as IFNAMSIZ-1, ie 15 characters. If the ACL specified
in the /etc/qemu-kvm/bridge.conf file denies access to a bridge interface with
a name long IFNAMSIZ-1, but it allows all other interfaces, it is possible for
a local attacker to use qemu-bridge-helper to create a tap device and attach it
to a denied bridge interface, thus bypassing the ACL. This could be used by the
attacker to get access to confidential data transmitted on the bridge.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2019-07/msg00245.html
Refere
arXiv
Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source ForksWith Global History Analysis
arxiv_fulltext·2026-01-28
Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source ForksWith Global History Analysis
195
195
41
4.76
2
1
100
1
3
100
51.3%
51%
8
4.1%
4%
5
2.6%
3%
5
2.6%
3%
5
2.6%
3%
4
2.1%
2%
4
2.1%
2%
4
2.1%
2%
4
2.1%
2%
4
2.1%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
3
1.5%
2%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
2
1.0%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
1
0.5%
1%
135
60
195
0.69
69
0.48
0.59
52
35
87
0.6
60
0.6
9
8
4
13
0.69
69
[Detecting One-day Vulnerabilities in Open-source Forks With Global History Analysis]Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source Forks With Global History Analysis
[Lefeuvre]Romain Lefeuvre
University of Rennes
Rennes
France
[email protected]
[Reux]Char
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00008.htmlhttp://www.openwall.com/lists/oss-security/2019/07/02/2http://www.openwall.com/lists/oss-security/2019/07/02/2http://www.securityfocus.com/bid/109054https://github.com/qemu/qemu/commit/03d7712b4bcd47bfe0fe14ba2fffa87e111fa086https://lists.debian.org/debian-lts-announce/2019/09/msg00021.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2019-07/msg00145.htmlhttps://seclists.org/bugtraq/2019/Aug/41https://seclists.org/bugtraq/2019/Sep/3https://security.gentoo.org/glsa/202003-66https://usn.ubuntu.com/4191-1/https://usn.ubuntu.com/4191-2/https://www.debian.org/security/2019/dsa-4506https://www.debian.org/security/2019/dsa-4512http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00008.htmlhttp://www.openwall.com/lists/oss-security/2019/07/02/2http://www.openwall.com/lists/oss-security/2019/07/02/2http://www.securityfocus.com/bid/109054https://github.com/qemu/qemu/commit/03d7712b4bcd47bfe0fe14ba2fffa87e111fa086https://lists.debian.org/debian-lts-announce/2019/09/msg00021.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2019-07/msg00145.htmlhttps://seclists.org/bugtraq/2019/Aug/41https://seclists.org/bugtraq/2019/Sep/3https://security.gentoo.org/glsa/202003-66https://usn.ubuntu.com/4191-1/https://usn.ubuntu.com/4191-2/https://www.debian.org/security/2019/dsa-4506https://www.debian.org/security/2019/dsa-4512
2019-07-03
Published