Out-of-bounds read in QEMU - CVE-2017-18030

 

Out-of-bounds read in QEMU - CVE-2017-18030

Published: March 12, 2018


Vulnerability identifier: #VU10940
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-18030
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to cause DoS condition on the target system.

The weakness exists in the cirrus_invalidate_region function in hw/display/cirrus_vga.c due to out-of-bounds read. A remote attacker can use vectors related to negative pitch, trigger memory error and cause QEMU process to crash.

Affected software

QEMU
Gentoo Linux
SUSE Linux
Oracle VM Server for x86

How to mitigate CVE-2017-18030

Install update from vendor's website.


External References

Related Security Bulletins