CVE-2018-18849: Medium severity Qemu Qemu vulnerability
Published Mar 17, 2019
·Updated
In Qemu 3.0.0, lsidomsgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msglen value.
Affected Software
9 affected componentsFixes available
Qemu Qemu=3.0.0
openSUSE Leap=15.0
openSUSE Leap=42.3
Fedoraproject Fedora=29
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
debian/qemu
1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u51:7.2+dfsg-7+deb12u181:7.2+dfsg-7+deb12u151:10.0.8+ds-0+deb13u11:10.0.2+ds-2+deb13u11:11.0.0+ds-21:11.0.1+ds-1
Remediation
Patch Available
Event History
Mar 17, 2019
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
Description
Mar 21, 2019
Data Sourced
via NVD·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·03:57 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·03:58 PM
Description
Jun 1, 2026
Data Sourced
via Debian·05:09 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-18849.
2
What is the severity level of CVE-2018-18849?
CVE-2018-18849 has a severity level of medium (5.5).
3
How does CVE-2018-18849 affect Qemu 3.0.0?
CVE-2018-18849 allows out-of-bounds access by triggering an invalid msg_len value in lsi_do_msgin in hw/scsi/lsi53c895a.c.
4
What software versions are affected by CVE-2018-18849?
CVE-2018-18849 affects Qemu 3.0.0.
5
Are there any remedies available for CVE-2018-18849?
Yes, there are specific package versions that provide remedies for CVE-2018-18849.