PT-2018-3378 · Qemu+3 · Qemu+3
Moguofang
·
Published
2018-11-08
·
Updated
2019-06-06
·
CVE-2018-18954
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
QEMU versions prior to 3.1
Description:
The issue is related to the pnv lpc do eccb function in the QEMU emulator, specifically in the hw/ppc/pnv lpc.c file. It involves a buffer data boundary read issue. Exploitation of this issue could allow an attacker to cause a denial of service and gain unauthorized access to PowerNV memory.
Recommendations:
For QEMU versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the pnv lpc do eccb function to minimize the risk of exploitation.
Fix
Out of bounds Read
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Qemu
Suse
Ubuntu