Out-of-bounds read in QEMU - CVE-2018-18849
Published: December 17, 2018
Vulnerability details
The vulnerability allows an adjacent attacker to cause DoS condition on the target system.
The vulnerability exists due to message length value in 'msg_len' could be invalid due to an invalid migration stream while writing a message in 'lsi_do_msgin'. An adjacent attacker can trigger out-of-bounds read and cause the service to crash.
Affected software
Opensuse
Fedora
qemu