Qemu · Qemu · CVE-2018-18954
Name of the Vulnerable Software and Affected Versions:
QEMU versions prior to 3.1
Description:
The issue is related to the pnv lpc do eccb function in the QEMU emulator, specifically in the hw/ppc/pnv lpc.c file. It involves a buffer data boundary read issue. Exploitation of this issue could allow an attacker to cause a denial of service and gain unauthorized access to PowerNV memory.
Recommendations:
For QEMU versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the pnv lpc do eccb function to minimize the risk of exploitation.