Out-of-bounds read in QEMU - CVE-2018-18849
Published: December 17, 2018
QEMU
Detailed vulnerability description
The vulnerability allows an adjacent attacker to cause DoS condition on the target system.
The vulnerability exists due to message length value in 'msg_len' could be invalid due to an invalid migration stream while writing a message in 'lsi_do_msgin'. An adjacent attacker can trigger out-of-bounds read and cause the service to crash.