CVE-2018-18954: Medium severity Qemu Qemu vulnerability
Last updated 25 August 2025
Other sources
The pnvlpcdoeccb function in hw/ppc/pnvlpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-18954?
CVE-2018-18954 is a vulnerability in Qemu that allows out-of-bounds write or read access to PowerNV memory.
How severe is CVE-2018-18954?
CVE-2018-18954 has a severity rating of medium, with a severity value of 5.5.
Which software versions are affected by CVE-2018-18954?
Versions 1:2.11+dfsg-1ubuntu7.8 and 1:2.12+dfsg-3ubuntu8.1 of Qemu for Ubuntu, version 3.1 and below of QEMU, and some versions of Debian are affected by CVE-2018-18954.
How can I fix CVE-2018-18954?
To fix CVE-2018-18954, you should update Qemu to version 3.1 or later if you are using QEMU, and update Debian or Ubuntu QEMU packages to the versions provided in the remedies.
Where can I find more information about CVE-2018-18954?
You can find more information about CVE-2018-18954 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00042.html, http://www.openwall.com/lists/oss-security/2018/11/06/6, and http://www.securityfocus.com/bid/105920.