Buffer overflow in QEMU - CVE-2018-17963

 

Buffer overflow in QEMU - CVE-2018-17963

Published: November 21, 2018


Vulnerability identifier: #VU15997
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17963
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to buffer overflow when qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX. A remote attacker can supply specially crafted packets over the network, trigger memory corruption and crash the Qemu process.


Affected software

QEMU
Red Hat Virtualization Manager
Debian Linux
Red Hat Enterprise Linux for IBM z Systems
Opensuse
Fedora
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat OpenStack
Red Hat OpenStack for IBM Power
qemu-kvm-rhev (Red Hat package)
qemu

How to mitigate CVE-2018-17963

Update to version 3.0.0.

QEMU - update to 3.0.0
qemu-kvm-rhev (Red Hat package) - update to 2.12.0-33.el7
qemu - update to 3.0.0-2.fc29

External References

Related Security Bulletins