CVE-2018-20191: Null Pointer Dereference
hw/rdma/vmw/pvrdmamain.c in QEMU does not implement a read operation (such as uarread by analogy to uarwrite), which allows attackers to cause a denial of service (NULL pointer dereference).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20191?
CVE-2018-20191 is categorized as a denial of service vulnerability due to a NULL pointer dereference.
How do I fix CVE-2018-20191?
To resolve CVE-2018-20191, update QEMU to a version that addresses this vulnerability, such as those specified in the remedy list.
Which versions of QEMU are affected by CVE-2018-20191?
CVE-2018-20191 affects QEMU versions up to 3.1.0, including specific Debian and Ubuntu releases listed in the vulnerability details.
Can CVE-2018-20191 be exploited remotely?
CVE-2018-20191 can be exploited by attackers to cause a denial of service, potentially without requiring local access.
What systems are vulnerable to CVE-2018-20191?
Systems running vulnerable versions of QEMU on Debian and Ubuntu, as well as specific Fedora versions, are affected by CVE-2018-20191.