CVE-2019-6778Out-of-bounds Write in Qemu

Severity
7.8HIGHNVD
EPSS
0.1%
top 77.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13

Description

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

debiandebian/qemu< qemu 1:3.1+dfsg-3 (bookworm)
debiandebian/slirp4netns< qemu 1:3.1+dfsg-3 (bookworm)
Debianqemu/qemu< 1:3.1+dfsg-3+3
Ubuntuqemu/qemu< 2.0.0+dfsg-2ubuntu1.45+2
NVDqemu/qemu3.0.0

Also affects: Fedora 29, 30, Ubuntu Linux 14.04, 16.04, 18.04, 18.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4wxm-q46g-3mcf: In QEMU 32022-05-13
OSV
qemu vulnerabilities2019-03-27
OSV
CVE-2019-6778: In QEMU 32019-03-21

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2019-03-27
Red Hat
QEMU: slirp: heap buffer overflow in tcp_emu()2019-01-11
Debian
CVE-2019-6778: qemu - In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.2019

💬Community

2
Bugzilla
CVE-2019-6778 qemu: slirp: heap buffer overflow in tcp_emu() [fedora-all]2019-01-24
Bugzilla
CVE-2019-6778 QEMU: slirp: heap buffer overflow in tcp_emu()2019-01-08