CVE-2018-20123: Medium severity Qemu Qemu vulnerability
Published Dec 17, 2018
·Updated
Last updated 25 August 2025
Other sources
pvrdmarealize in hw/rdma/vmw/pvrdmamain.c in QEMU has a Memory leak after an initialisation error.
— Launchpad
Affected Software
7 affected componentsFixes available
Qemu Qemu<=3.1.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Fedoraproject Fedora=30
debian/qemu
1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u51:7.2+dfsg-7+deb12u181:7.2+dfsg-7+deb12u151:10.0.7+ds-0+deb13u11:10.0.2+ds-2+deb13u11:10.2.1+ds-1
Remediation
Patch Available
Event History
Dec 17, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·05:44 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·05:44 PM
Description
Feb 23, 2026
Data Sourced
via Debian·04:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-20123?
CVE-2018-20123 is classified as a medium severity vulnerability due to the potential for a memory leak.
2
How do I fix CVE-2018-20123?
To fix CVE-2018-20123, update your QEMU software to a patched version that resolves the memory leak issue.
3
Which software versions are affected by CVE-2018-20123?
CVE-2018-20123 affects specific versions of QEMU, including those prior to 3.1.0 and certain Debian and Ubuntu releases.
4
What type of vulnerability is CVE-2018-20123?
CVE-2018-20123 is a memory leak vulnerability that occurs after an initialization error in QEMU.
5
Can CVE-2018-20123 be exploited remotely?
CVE-2018-20123 is not directly categorized as a remote vulnerability but may impact services that utilize QEMU.