First published: Thu Nov 15 2018(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU qemu | <3.1 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
openSUSE Leap | =42.3 | |
debian/qemu | 1:5.2+dfsg-11+deb11u3 1:5.2+dfsg-11+deb11u2 1:7.2+dfsg-7+deb12u7 1:9.0.2+ds-2 1:9.1.0+ds-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18954 is a vulnerability in Qemu that allows out-of-bounds write or read access to PowerNV memory.
CVE-2018-18954 has a severity rating of medium, with a severity value of 5.5.
Versions 1:2.11+dfsg-1ubuntu7.8 and 1:2.12+dfsg-3ubuntu8.1 of Qemu for Ubuntu, version 3.1 and below of QEMU, and some versions of Debian are affected by CVE-2018-18954.
To fix CVE-2018-18954, you should update Qemu to version 3.1 or later if you are using QEMU, and update Debian or Ubuntu QEMU packages to the versions provided in the remedies.
You can find more information about CVE-2018-18954 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00042.html, http://www.openwall.com/lists/oss-security/2018/11/06/6, and http://www.securityfocus.com/bid/105920.