Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-20815

Опубликовано: 14 дек. 2018
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.

A heap buffer overflow issue was found in the load_device_tree() function of QEMU, which is invoked to load a device tree blob at boot time. It occurs due to device tree size manipulation before buffer allocation, which could overflow a signed int type. A user/process could use this flaw to potentially execute arbitrary code on a host system with privileges of the QEMU process.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 5xenNot affected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat OpenStack Platform 8 (Liberty)qemu-kvm-rhevAffected
Red Hat Enterprise Linux 7qemu-kvm-maFixedRHSA-2019:188129.07.2019
Red Hat Enterprise Linux 8virtFixedRHSA-2019:117514.05.2019
Red Hat OpenStack Platform 10.0 (Newton)qemu-kvm-rhevFixedRHSA-2019:172310.07.2019
Red Hat OpenStack Platform 13.0 (Queens)qemu-kvm-rhevFixedRHSA-2019:174310.07.2019
Red Hat OpenStack Platform 14.0 (Rocky)qemu-kvm-rhevFixedRHSA-2019:166702.07.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1693101QEMU: device_tree: heap buffer overflow while loading device tree blob

EPSS

Процентиль: 81%
0.01604
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.

CVSS3: 9.8
nvd
около 6 лет назад

In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.

CVSS3: 9.8
debian
около 6 лет назад

In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated ...

CVSS3: 9.8
github
около 3 лет назад

In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.

CVSS3: 7
fstec
больше 6 лет назад

Уязвимость функции load_device_tree эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнять произвольный код

EPSS

Процентиль: 81%
0.01604
Низкий

7 High

CVSS3