PT-2018-3507 · Qemu+2 · Qemu+2

Li Quang

+1

·

Published

2018-12-13

·

Updated

2024-06-15

·

CVE-2018-20216

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: QEMU (affected versions not specified)
Description: The issue is related to the pvrdma idx ring has function in the PVRDMA emulator of QEMU, which can lead to an infinite loop due to an unreachable exit condition. This can be exploited by a remote attacker to cause a denial of service. The problem arises from un-checked return values in hw/rdma/vmw/pvrdma dev ring.c, specifically the mishandling of -1 return values.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unchecked Return Value

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1973
ALT-PU-2019-1990
BDU:2020-03211
CVE-2018-20216
OPENSUSE-SU-2024:11287-1
USN-3923-1

Affected Products

Alt Linux
Qemu
Ubuntu