CVE-2018-5748: High severity redhat libvirt vulnerability
A flaw was found in Qemu. A lack of restriction for the amount of data read by QEMU Monitor socket can lead to denial of service by exhaustion of memory resources.
References:
https://www.redhat.com/archives/libvir-list/2017-December/msg00749.html
Other sources
qemu/qemumonitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libvirtto a version that resolves this vulnerability.Fixed in 0:0.10.2-64.el6 - Upgrade
Upgrade
redhat/libvirtto a version that resolves this vulnerability.Fixed in 0:3.9.0-14.el7_5.4 - Upgrade
Upgrade
debian/libvirtto a version that resolves this vulnerability.Fixed in 7.0.0-3+deb11u3Fixed in 9.0.0-4+deb12u2Fixed in 11.3.0-3+deb13u2Fixed in 12.0.0-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2018-5748?
CVE-2018-5748 is a vulnerability in libvirt that allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
How severe is CVE-2018-5748?
CVE-2018-5748 is considered high severity with a CVSS score of 7.5.
Which software versions are affected by CVE-2018-5748?
The affected software versions include libvirt 0.10.2-64.el6, 3.9.0-14.el7_5.4, and various versions on Debian and Ubuntu.
How can I fix CVE-2018-5748?
To fix CVE-2018-5748, update libvirt to version 0.10.2-64.el6 or 3.9.0-14.el7_5.4, or install the latest available patches for Debian and Ubuntu.
Where can I find more information about CVE-2018-5748?
You can find more information about CVE-2018-5748 in the references provided: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1535785) and [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2018:1396).