CVE-2018-17958: Buffer Overflow
An integer overflow issue was found in the RTL8139 NIC emulation in QEMU. It could occur while receiving packets over the network if the size value is greater than INTMAX. Such overflow would lead to stack buffer overflow issue. A user inside guest could use this flaw to crash the QEMU process, resulting in DoS scenario.
Other sources
Qemu emulator built with the RTL8139 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network.
A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
Upstream fix: ------------- -> https://lists.gnu.org/archive/html/qemu-devel/2018-09/msg03269.html
Reference: ---------- -> https://www.openwall.com/lists/oss-security/2018/10/08/1
— Red Hat
Qemu has a Buffer Overflow in rtl8139doreceive in hw/net/rtl8139.c because an incorrect integer data type is used.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2018-17958?
CVE-2018-17958 is a vulnerability in the RTL8139 NIC emulation in QEMU that could lead to a stack buffer overflow issue.
How severe is CVE-2018-17958?
CVE-2018-17958 has a severity rating of 7.5 (high).
What software versions are affected by CVE-2018-17958?
QEMU versions up to 3.0.1, QEMU-KVM-RHEV version 10:2.12.0-33.el7, and various versions of Ubuntu, Debian, Canonical Ubuntu Linux, Redhat Virtualization, and Redhat Virtualization Manager are affected by CVE-2018-17958.
How do I fix CVE-2018-17958 on Redhat?
To fix CVE-2018-17958 on Redhat, update the qemu-kvm-rhev package to version 10:2.12.0-33.el7 or later.
How can I mitigate CVE-2018-17958 on Ubuntu?
To mitigate CVE-2018-17958 on Ubuntu, update the qemu package to version 1:2.12+dfsg-3ubuntu9 or later.