CVE-2018-20125: Null Pointer Dereference
Published Dec 20, 2018
·Updated
hw/rdma/vmw/pvrdmacmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in createcqring or createqprings.
Affected Software
6 affected componentsFixes available
Qemu Qemu<=3.1.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
debian/qemu
1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u51:7.2+dfsg-7+deb12u181:7.2+dfsg-7+deb12u151:10.0.7+ds-0+deb13u11:10.0.2+ds-2+deb13u11:10.2.1+ds-1
Remediation
Patch Available
Event History
Dec 20, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:58 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·05:44 PM
RemedyDescriptionSeverityAffected Software
Feb 23, 2026
Data Sourced
via Debian·04:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-20125?
CVE-2018-20125 has a severity rating that allows for denial of service due to a NULL pointer dereference or excessive memory allocation.
2
How do I fix CVE-2018-20125?
To fix CVE-2018-20125, upgrade to the latest patched version of QEMU.
3
What are the affected versions for CVE-2018-20125?
CVE-2018-20125 affects QEMU versions up to and including 3.1.0.
4
Can CVE-2018-20125 be exploited remotely?
Yes, CVE-2018-20125 could potentially be exploited remotely leading to a denial of service.
5
What software is impacted by CVE-2018-20125?
CVE-2018-20125 impacts QEMU, affecting multiple distributions including Debian and Ubuntu.