Heap-based buffer overflow in QEMU - CVE-2018-11806

 

Heap-based buffer overflow in QEMU - CVE-2018-11806

Published: June 16, 2018 / Updated: June 18, 2018


Vulnerability identifier: #VU13375
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11806
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.

The vulnerability exists due to heap-based buffer overflow when insufficient input and validation checking of Slirp networking back-end processes by the m_cat function, as defined in the slirp/mbuf.c source code file. A remote attacker can send malformed, fragmented packets, trigger memory corruption and cause the QEMU process to crash.


Affected software

QEMU
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
Opensuse
Fedora
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat OpenStack
Red Hat OpenStack for IBM Power
qemu

How to mitigate CVE-2018-11806

Install update from vendor's website.

qemu - addressed in versions 2.10.2-1.fc27, 2.11.2-2.fc28

External References

Related Security Bulletins