Heap-based buffer overflow in QEMU - CVE-2018-11806
Published: June 16, 2018 / Updated: June 18, 2018
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The vulnerability exists due to heap-based buffer overflow when insufficient input and validation checking of Slirp networking back-end processes by the m_cat function, as defined in the slirp/mbuf.c source code file. A remote attacker can send malformed, fragmented packets, trigger memory corruption and cause the QEMU process to crash.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
Opensuse
Fedora
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat OpenStack
Red Hat OpenStack for IBM Power
qemu
How to mitigate CVE-2018-11806
External References
Related Security Bulletins
- Denial of service in QEMU
- OpenSUSE Linux update for xen
- OpenSUSE Linux update for qemu
- Amazon Linux AMI update for qemu-kvm
- Red Hat update for qemu
- OpenSUSE Linux update for qemu
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-ma
- Red Hat update for qemu-kvm
- Red Hat update for qemu-kvm
- Fedora 28 update for qemu
- Fedora 27 update for qemu