ALT-PU-2018-1657-1
Closed vulnerabilities
BDU:2018-00091
Уязвимость функции post_load (hw/input/ps2.c) эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю выполнить чтение за границами буфера в динамической памяти
BDU:2018-01508
Уязвимость функции load_multiboot эмулятора аппаратного обеспечения Qemu, связанная с записью за границами буфера памяти, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2019-00716
Уязвимость функции vga_draw_text эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-00721
Уязвимость эмулятора аппаратного обеспечения QEMU позволяет записывать данные за пределами заданного буфера, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2017-16845
hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
- 101923
- 101923
- [debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update
- [debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update
- [qemu-devel] 20171116 [PATCH v2] ps2: check PS2Queue indices in post_load routine
- [qemu-devel] 20171116 [PATCH v2] ps2: check PS2Queue indices in post_load routine
- USN-3575-1
- USN-3575-1
- USN-3649-1
- USN-3649-1
- DSA-4213
- DSA-4213
Modified: 2024-11-21
CVE-2018-5683
The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.
- [oss-security] 20180115 CVE-2018-5683 Qemu: Out-of-bounds read in vga_draw_text routine
- [oss-security] 20180115 CVE-2018-5683 Qemu: Out-of-bounds read in vga_draw_text routine
- 102518
- 102518
- RHSA-2018:0816
- RHSA-2018:0816
- RHSA-2018:1104
- RHSA-2018:1104
- RHSA-2018:2162
- RHSA-2018:2162
- [debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update
- [debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update
- [Qemu-devel] 20180112 Re: [Qemu-devel] [PATCH v3] vga: check the validation of memory addr when draw text
- [Qemu-devel] 20180112 Re: [Qemu-devel] [PATCH v3] vga: check the validation of memory addr when draw text
- USN-3575-1
- USN-3575-1
- DSA-4213
- DSA-4213
Modified: 2024-11-21
CVE-2018-7550
The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.
- 103181
- 103181
- RHSA-2018:1369
- RHSA-2018:1369
- RHSA-2018:2462
- RHSA-2018:2462
- https://bugzilla.redhat.com/show_bug.cgi?id=1549798
- https://bugzilla.redhat.com/show_bug.cgi?id=1549798
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-f49v-45qp-cv53
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-f49v-45qp-cv53
- [debian-lts-announce] 20180417 [SECURITY] [DLA 1350-1] qemu-kvm security update
- [debian-lts-announce] 20180417 [SECURITY] [DLA 1350-1] qemu-kvm security update
- [debian-lts-announce] 20180417 [SECURITY] [DLA 1351-1] qemu security update
- [debian-lts-announce] 20180417 [SECURITY] [DLA 1351-1] qemu security update
- [debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update
- [debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update
- [qemu-devel] 20180228 [PATCH] multiboot: check mh_load_end_addr address field
- [qemu-devel] 20180228 [PATCH] multiboot: check mh_load_end_addr address field
- USN-3649-1
- USN-3649-1
- DSA-4213
- DSA-4213
Modified: 2024-11-21
CVE-2018-7858
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
- openSUSE-SU-2019:1074
- openSUSE-SU-2019:1074
- [oss-security] 20180309 CVE-2018-7858 Qemu: cirrus: OOB access when updating vga display
- [oss-security] 20180309 CVE-2018-7858 Qemu: cirrus: OOB access when updating vga display
- 103350
- 103350
- RHSA-2018:1369
- RHSA-2018:1369
- RHSA-2018:1416
- RHSA-2018:1416
- RHSA-2018:2162
- RHSA-2018:2162
- https://bugzilla.redhat.com/show_bug.cgi?id=1553402
- https://bugzilla.redhat.com/show_bug.cgi?id=1553402
- [qemu-devel] 20180308 [PATCH] vga: fix region calculation
- [qemu-devel] 20180308 [PATCH] vga: fix region calculation
- USN-3649-1
- USN-3649-1