Описание
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.
An out-of-bounds read access issue was found in the VGA display emulator built into the Quick emulator (QEMU). It could occur while reading VGA memory to update graphics display. A privileged user/process inside guest could use this flaw to crash the QEMU process on the host resulting in denial of service situation.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | kvm | Will not fix | ||
Red Hat Enterprise Linux 5 | xen | Will not fix | ||
Red Hat Enterprise Linux 6 | qemu-kvm-rhev | Affected | ||
Red Hat Enterprise Linux 7 | qemu-kvm-rhev | Affected | ||
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | qemu-kvm-rhev | Will not fix | ||
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | qemu-kvm-rhev | Will not fix | ||
Red Hat Enterprise Linux 6 | qemu-kvm | Fixed | RHSA-2018:2162 | 10.07.2018 |
Red Hat Enterprise Linux 7 | qemu-kvm | Fixed | RHSA-2018:0816 | 10.04.2018 |
Red Hat OpenStack Platform 10.0 (Newton) | qemu-kvm-rhev | Fixed | RHSA-2018:1113 | 11.04.2018 |
Red Hat OpenStack Platform 11.0 (Ocata) | qemu-kvm-rhev | Fixed | RHSA-2018:1113 | 11.04.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
3 Low
CVSS3
2.3 Low
CVSS2
Связанные уязвимости
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.
QEMU (aka Quick Emulator), when built with the VGA display emulator su ...
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.
EPSS
3 Low
CVSS3
2.3 Low
CVSS2