CVE-2019-9824
published 2019-06-03CVE-2019-9824: tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
PriorityP422medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.52%
40.8th percentile
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:3.1+dfsg-6 (bookworm) | qemu 1:3.1+dfsg-6 (bookworm) |
| debian | slirp4netns | < qemu 1:3.1+dfsg-6 (bookworm) | qemu 1:3.1+dfsg-6 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:3.1+dfsg-6 | 1:3.1+dfsg-6 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-6 | 1:3.1+dfsg-6 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-6 | 1:3.1+dfsg-6 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-6 | 1:3.1+dfsg-6 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.46 | 2.0.0+dfsg-2ubuntu1.46 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.38 | 1:2.5+dfsg-5ubuntu10.38 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.13 | 1:2.11+dfsg-1ubuntu7.13 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.6MEDIUM
vendor_ubuntu5.6MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hx33-mww2-6mf5: tcp_emu in slirp/tcp_subr
ghsa_unreviewed·2022-05-24
CVE-2019-9824 [MEDIUM] GHSA-hx33-mww2-6mf5: tcp_emu in slirp/tcp_subr
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
OSV
CVE-2019-9824: tcp_emu in slirp/tcp_subr
osv·2019-06-03·CVSS 5.5
CVE-2019-9824 [MEDIUM] CVE-2019-9824: tcp_emu in slirp/tcp_subr
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
OSV
qemu update
osv·2019-05-14·CVSS 5.6
[MEDIUM] qemu update
qemu update
Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan
Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa
Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos,
Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss
discovered that memory previously stored in microarchitectural fill buffers
of an Intel CPU core may be exposed to a malicious process that is
executing on the same CPU core. A local attacker could use this to expose
sensitive information. (CVE-2018-12130)
Brandon Falk, Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Stephan
van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh
Razavi, Herbert Bos, and Cristiano Giuffrida discovered that memory
previously stored in microarch
Ubuntu
QEMU update
vendor_ubuntu·2019-05-14·CVSS 5.6
CVE-2018-12126 [MEDIUM] QEMU update
Title: QEMU update
Summary: Several issues were addressed in QEMU.
Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan
Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa
Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos,
Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss
discovered that memory previously stored in microarchitectural fill buffers
of an Intel CPU core may be exposed to a malicious process that is
executing on the same CPU core. A local attacker could use this to expose
sensitive information. (CVE-2018-12130)
Brandon Falk, Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Stephan
van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh
Razavi, Herbert Bos, and Cristiano Giuffri
Red Hat
QEMU: slirp: information leakage in tcp_emu() due to uninitialized stack variables
vendor_redhat·2019-03-01·CVSS 5.5
CVE-2019-9824 [MEDIUM] CWE-200 QEMU: slirp: information leakage in tcp_emu() due to uninitialized stack variables
QEMU: slirp: information leakage in tcp_emu() due to uninitialized stack variables
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
Package: kvm (Red Hat Enterprise Linux 5) - Will not fix
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm-rhev (Red Hat OpenStack Platform 8 (Liberty)) - Fix deferred
Package: qemu-kvm-rhev (Red Hat OpenStack Platform 9 (Mitaka)) - Fix deferred
Debian
CVE-2019-9824: qemu - tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninit...
vendor_debian·2019·CVSS 5.5
CVE-2019-9824 [MEDIUM] CVE-2019-9824: qemu - tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninit...
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-6)
bullseye: resolved (fixed in 1:3.1+dfsg-6)
forky: resolved (fixed in 1:3.1+dfsg-6)
sid: resolved (fixed in 1:3.1+dfsg-6)
trixie: resolved (fixed in 1:3.1+dfsg-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9824 qemu: Slirp: information leakage in tcp_emu() due to uninitialized stack variables [fedora-all]
bugzilla·2019-03-18·CVSS 5.5
CVE-2019-9824 [MEDIUM] CVE-2019-9824 qemu: Slirp: information leakage in tcp_emu() due to uninitialized stack variables [fedora-all]
CVE-2019-9824 qemu: Slirp: information leakage in tcp_emu() due to uninitialized stack variables [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2019-9824 QEMU: slirp: information leakage in tcp_emu() due to uninitialized stack variables
bugzilla·2019-02-19·CVSS 5.5
CVE-2019-9824 [MEDIUM] CVE-2019-9824 QEMU: slirp: information leakage in tcp_emu() due to uninitialized stack variables
CVE-2019-9824 QEMU: slirp: information leakage in tcp_emu() due to uninitialized stack variables
An information leak issue was found in the SLiRP networking implementation of the QEMU emulator. It occurs in tcp_emu() routine while emulating
Identification protocol and crafted/malformed messages are sent making it return uninitialized variables.
A user/process could use this flaw to read uninitialised stack memory contents from the QEMU process resulting in information leakage.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2019-03/msg01871.html
Reference:
-> https://www.openwall.com/lists/oss-security/2019/03/18/1
Discussion:
Acknowledgments:
Name: William Bowling
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1689794]
---
This issue h
https://access.redhat.com/errata/RHSA-2019:1650https://access.redhat.com/errata/RHSA-2019:2078https://access.redhat.com/errata/RHSA-2019:2425https://access.redhat.com/errata/RHSA-2019:2553https://access.redhat.com/errata/RHSA-2019:3345https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVDHJB2QKXNDU7OFXIHIL5O5VN5QCSZL/https://lists.gnu.org/archive/html/qemu-devel/2019-03/msg00400.htmlhttps://access.redhat.com/errata/RHSA-2019:1650https://access.redhat.com/errata/RHSA-2019:2078https://access.redhat.com/errata/RHSA-2019:2425https://access.redhat.com/errata/RHSA-2019:2553https://access.redhat.com/errata/RHSA-2019:3345https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVDHJB2QKXNDU7OFXIHIL5O5VN5QCSZL/https://lists.gnu.org/archive/html/qemu-devel/2019-03/msg00400.html
2019-06-03
Published