CVE-2018-18849
21.03.2019, 16:00
In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.Enginsight
| Vendor | Product | Version |
|---|---|---|
| qemu | qemu | 3.0.0 |
| opensuse | leap | 15.0 |
| opensuse | leap | 42.3 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qemu |
| ||||||||||||||||||
| qemu-kvm |
|
Common Weakness Enumeration
References