PT-2018-3378 · Qemu+3 · Qemu+3

Moguofang

·

Published

2018-11-08

·

Updated

2019-06-06

·

CVE-2018-18954

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: QEMU versions prior to 3.1
Description: The issue is related to the pnv lpc do eccb function in the QEMU emulator, specifically in the hw/ppc/pnv lpc.c file. It involves a buffer data boundary read issue. Exploitation of this issue could allow an attacker to cause a denial of service and gain unauthorized access to PowerNV memory.
Recommendations: For QEMU versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the pnv lpc do eccb function to minimize the risk of exploitation.

Fix

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2870
BDU:2020-00704
CVE-2018-18954
DSA-4454-1
DSA-4454-2
OPENSUSE-SU-2019:0254-1
OPENSUSE-SU-2019_0254-1
OPENSUSE-SU-2019_1074-1
SUSE-SU-2019:0423-1
SUSE-SU-2019:0435-1
SUSE-SU-2019:0582-1
USN-3826-1

Affected Products

Alt Linux
Qemu
Suse
Ubuntu