Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation...
Vulnerability Description
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-10839
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10839
- https://www.debian.org/security/2018/dsa-4338
- https://usn.ubuntu.com/3826-1/
- https://www.openwall.com/lists/oss-security/2018/10/08/1
- https://lists.debian.org/debian-lts-announce/2018/11/msg00038.html
- https://lists.gnu.org/archive/html/qemu-devel/2018-09/msg03273.html
- https://access.redhat.com/errata/RHSA-2019:2892
Affected Vendor
The QEMU Project
View all reports →