CVE-2018-20126: Medium severity Qemu Qemu vulnerability
Published Dec 20, 2018
·Updated
hw/rdma/vmw/pvrdmacmd.c in QEMU allows createcq and createqp memory leaks because errors are mishandled.
Affected Software
8 affected componentsFixes available
Qemu Qemu<=3.1.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
openSUSE Leap=15.0
openSUSE Leap=15.1
debian/qemu
1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u51:7.2+dfsg-7+deb12u181:7.2+dfsg-7+deb12u151:10.0.7+ds-0+deb13u11:10.0.2+ds-2+deb13u11:10.2.1+ds-1
Remediation
Patch Available
Event History
Dec 20, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:58 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·05:44 PM
RemedyDescriptionSeverityAffected Software
Feb 23, 2026
Data Sourced
via Debian·04:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-20126?
CVE-2018-20126 is classified as a medium severity vulnerability due to memory leaks caused by mishandled errors in QEMU.
2
How do I fix CVE-2018-20126?
To fix CVE-2018-20126, upgrade to a patched version of QEMU that resolves the memory leak issues.
3
Which versions of QEMU are affected by CVE-2018-20126?
CVE-2018-20126 affects all versions of QEMU up to 3.1.0 and specific Debian and Ubuntu releases as noted.
4
What is the impact of CVE-2018-20126 on QEMU?
The impact of CVE-2018-20126 includes potential memory exhaustion over time, which could lead to denial of service.
5
Is CVE-2018-20126 present in Ubuntu 16.04?
Yes, CVE-2018-20126 is present in Ubuntu 16.04 along with several other affected versions of Ubuntu.