CVE-2018-19364: Use After Free
Published Dec 13, 2018
·Updated
hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.
Affected Software
12 affected componentsFixes available
Qemu Qemu<=3.0.0
Qemu Qemu=3.1.0-rc0
Qemu Qemu=3.1.0-rc1
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Fedoraproject Fedora=29
openSUSE Leap=42.3
debian/qemu
1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u51:7.2+dfsg-7+deb12u181:7.2+dfsg-7+deb12u151:10.0.8+ds-0+deb13u11:10.0.2+ds-2+deb13u11:11.0.0+ds-21:11.0.1+ds-1
Remediation
Patch Available
Event History
Dec 13, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·03:57 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·03:58 PM
Description
Jun 1, 2026
Data Sourced
via Debian·05:09 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-19364.
2
What is the title of this vulnerability?
The title of this vulnerability is 'hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.'
3
What is the severity of CVE-2018-19364?
The severity of CVE-2018-19364 is medium, with a CVSS score of 5.5.
4
What software versions are affected by this vulnerability?
QEMU versions up to and including 3.0.0 are affected by this vulnerability.
5
How can I fix the vulnerability CVE-2018-19364?
To fix the vulnerability CVE-2018-19364, you should update to a version of QEMU that is not affected by the issue.