Integer overflow in QEMU - CVE-2018-17958

 

Integer overflow in QEMU - CVE-2018-17958

Published: December 17, 2018


Vulnerability identifier: #VU16554
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17958
CWE-ID: CWE-190
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to cause DoS condition on the target system.

The vulnerability exists due to a boundary error in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used. An adjacent attacker can trigger integer overflow and cause the service to crash.


Affected software

QEMU
Red Hat Virtualization Manager
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Opensuse
Fedora
qemu-kvm-rhev (Red Hat package)
qemu

How to mitigate CVE-2018-17958

Install update from vendor's website.

qemu-kvm-rhev (Red Hat package) - update to 2.12.0-33.el7
qemu - update to 3.0.0-2.fc29

External References

Related Security Bulletins