CVE-2018-7858: Medium severity Qemu Qemu vulnerability
Last updated 25 August 2025
Other sources
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
— Launchpad
Quick emulator(QEMU) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. It could occur while updating VGA display, after guest has adjusted the display dimensions.
A privileged user inside guest could use this flaw to crash the Qemu process resulting in DoS.
Upstream patch: --------------- -> https://lists.nongnu.org/archive/html/qemu-devel/2018-03/msg02174.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2018/03/09/1
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qemuto a version that resolves this vulnerability.Fixed in 1:5.2+dfsg-11+deb11u3Fixed in 1:5.2+dfsg-11+deb11u5Fixed in 1:7.2+dfsg-7+deb12u18Fixed in 1:7.2+dfsg-7+deb12u15Fixed in 1:10.0.11+ds-0+deb13u1Fixed in 1:10.0.2+ds-2+deb13u1Fixed in 1:11.0.2+ds-2
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7858?
CVE-2018-7858 has a medium severity level as it can cause a denial of service due to a crash.
How do I fix CVE-2018-7858?
To fix CVE-2018-7858, update QEMU to a version later than 2.11.2 that doesn't include the vulnerability.
Which software is affected by CVE-2018-7858?
CVE-2018-7858 affects QEMU with Cirrus CLGD 54xx VGA Emulator support on various distributions, specifically versions up to 2.11.2.
Can CVE-2018-7858 be exploited remotely?
CVE-2018-7858 is not remotely exploitable as it requires local guest OS privileged user access to trigger the vulnerability.
Is there any workaround for CVE-2018-7858?
There are no known workarounds for CVE-2018-7858; upgrading to a patched version is the recommended course of action.