CVE-2019-8934: Low severity qemu vulnerability
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8934?
CVE-2019-8934 has a moderate severity rating due to the potential for information exposure in virtualized environments.
How do I fix CVE-2019-8934?
To fix CVE-2019-8934, update QEMU to a version higher than 3.1.0 or apply the necessary patches provided by your operating system distributor.
Which versions of QEMU are affected by CVE-2019-8934?
CVE-2019-8934 affects QEMU versions up to and including 3.1.0.
What types of systems are impacted by CVE-2019-8934?
CVE-2019-8934 primarily impacts systems using QEMU virtualization, including Debian and openSUSE distributions.
What is the main issue described in CVE-2019-8934?
CVE-2019-8934 describes an information exposure vulnerability where the hypervisor shares sensitive system attributes with a guest.