PT-2018-2790 · Qemu+5 · Qemu+5

Published

2018-12-14

·

Updated

2024-06-15

·

CVE-2018-20815

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU version 3.1.0
Description The issue is related to a buffer overflow risk in the load device tree function of the QEMU hardware emulator, specifically due to the use of the deprecated load image function. This could potentially allow an attacker to execute arbitrary code.
Recommendations For QEMU version 3.1.0, consider avoiding the use of the load device tree function until a patch is available, or refrain from using the deprecated load image function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1973
ALT-PU-2019-1990
BDU:2019-01871
CESA-2019_1175
CVE-2018-20815
DLA-1781-1
DSA-4506-1
OPENSUSE-SU-2019:1405-1
OPENSUSE-SU-2019_1274-1
OPENSUSE-SU-2019_1405-1
OPENSUSE-SU-2019_1419-1
OPENSUSE-SU-2024:11287-1
RHSA-2019:1175
RHSA-2019:1667
RHSA-2019:1723
RHSA-2019:1743
RHSA-2019:1881
RHSA-2019:1968
RHSA-2019:2507
RHSA-2019:2553
RHSA-2019_1175
RHSA-2019_1881
SUSE-SU-2019:1238-1
SUSE-SU-2019:1239-1
SUSE-SU-2019:1268-1
SUSE-SU-2019:1269-1
SUSE-SU-2019:1272-1
SUSE-SU-2019:1348-1
SUSE-SU-2019:1349-1
SUSE-SU-2019:1371-1
SUSE-SU-2019:14052-1
SUSE-SU-2019:14053-1
SUSE-SU-2019:14063-1
SUSE-SU-2019:14201-1
SUSE-SU-2019_14052-1
SUSE-SU-2019_14063-1
USN-3978-1

Affected Products

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu