CVE-2018-16847: High severity Qemu Qemu vulnerability
An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvmecmbops routines in nvme device. A guest user/process could use this flaw to crash the QEMU process resulting in DoS or potentially run arbitrary code with privileges of the QEMU process.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16847?
CVE-2018-16847 is an OOB heap buffer r/w access vulnerability in the NVM Express Controller emulation in QEMU, which could result in denial of service (DoS) or arbitrary code execution.
What is the severity of CVE-2018-16847?
The severity of CVE-2018-16847 is high with a CVSS score of 7.8.
How does CVE-2018-16847 affect QEMU?
CVE-2018-16847 affects the NVM Express Controller emulation in QEMU, allowing a guest user/process to crash QEMU or potentially execute arbitrary code with the privileges of the QEMU process.
Which software versions are affected by CVE-2018-16847?
QEMU versions up to 3.0.0, 3.1.0-rc0, and 3.1.0-rc1 are affected, as well as specific versions of QEMU on Ubuntu 14.04, 16.04, 18.04, and 18.10, and certain versions of QEMU on Debian systems.
How can I fix CVE-2018-16847?
To fix CVE-2018-16847, update QEMU to version 1:2.11+dfsg-1ubuntu7.8 on Ubuntu, 1:2.12+dfsg-3ubuntu8.1 on Ubuntu 18.04 (cosmic), or the appropriate fixed versions on other affected systems.