Unrated severityNVD Advisory· Published Nov 15, 2018· Updated Aug 5, 2024
CVE-2018-18954
CVE-2018-18954
Description
The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
Affected products
8- osv-coords8 versionspkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4
< 2.9.1-6.28.1+ 7 more
- (no CPE)range: < 2.9.1-6.28.1
- (no CPE)range: < 2.11.2-5.8.1
- (no CPE)range: < 2.11.2-9.20.1
- (no CPE)range: < 2.11.2-9.20.1
- (no CPE)range: < 2.9.1-6.28.1
- (no CPE)range: < 2.11.2-5.8.1
- (no CPE)range: < 2.9.1-6.28.1
- (no CPE)range: < 2.11.2-5.8.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- lists.opensuse.org/opensuse-security-announce/2019-03/msg00042.htmlmitrevendor-advisoryx_refsource_SUSE
- usn.ubuntu.com/3826-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.debian.org/security/2019/dsa-4454mitrevendor-advisoryx_refsource_DEBIAN
- www.openwall.com/lists/oss-security/2018/11/06/6mitremailing-listx_refsource_MLIST
- www.securityfocus.com/bid/105920mitrevdb-entryx_refsource_BID
- lists.gnu.org/archive/html/qemu-devel/2018-11/msg00446.htmlmitremailing-listx_refsource_MLIST
- seclists.org/bugtraq/2019/May/76mitremailing-listx_refsource_BUGTRAQ
News mentions
0No linked articles in our index yet.