Improper input validation in QEMU - CVE-2018-15746

 

Improper input validation in QEMU - CVE-2018-15746

Published: December 16, 2018 / Updated: December 17, 2018


Vulnerability identifier: #VU16553
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15746
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to cause DoS condition on the target system.

The vulnerability exists in qemu-seccomp.c due to an error when processing malicious input. An adjacent attacker can leverage mishandling of the seccomp policy for threads other than the main thread and cause the service to crash.


Affected software

QEMU
Amazon Linux AMI
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Opensuse
Fedora
qemu-kvm (Red Hat package)
qemu-kvm-ma (Red Hat package)
qemu
Red Hat OpenStack
Red Hat OpenStack for IBM Power

How to mitigate CVE-2018-15746

Install update from vendor's website.

qemu-kvm (Red Hat package) - update to 1.5.3-175.el7
qemu-kvm-ma (Red Hat package) - update to 2.12.0-48.el7
qemu - update to 3.0.0-2.fc29

External References

Related Security Bulletins