PT-2019-6086 · Qemu+3 · Qemu+3

Riccardo Schirone

·

Published

2019-07-01

·

Updated

2024-06-15

·

CVE-2019-13164

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions 3.1 through 4.0.0
Description The issue is related to a security flaw in the qemu-bridge-helper.c function of the QEMU hardware emulator. This flaw can lead to an ACL bypass due to the lack of limitation on the network interface name size, which is obtained from bridge.conf or a --br=bridge option. The exploitation of this flaw may allow an attacker to gain unauthorized access to information, cause a denial of service, or impact the availability of information.
Recommendations For QEMU versions 3.1 through 4.0.0, consider restricting access to the qemu-bridge-helper.c function until a patch is available. As a temporary workaround, limit the network interface name size to the IFNAMSIZ size to prevent potential ACL bypass. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2496
ALT-PU-2019-2534
BDU:2021-05168
CVE-2019-13164
DLA-1927-1
DSA-4506-1
DSA-4512-1
OPENSUSE-SU-2019:2041-1
OPENSUSE-SU-2019:2059-1
OPENSUSE-SU-2019_2041-1
OPENSUSE-SU-2019_2059-1
OPENSUSE-SU-2024:11287-1
SUSE-SU-2019:14151-1
SUSE-SU-2019:2157-1
SUSE-SU-2019:2192-1
SUSE-SU-2019:2221-1
SUSE-SU-2019:2246-1
SUSE-SU-2019:2353-1
SUSE-SU-2019_14151-1
USN-4191-1
USN-4191-2

Affected Products

Alt Linux
Qemu
Suse
Ubuntu