Back

CRITICAL

Qemu: cirrus: heap buffer overflow via vnc connection

Published Jul 27, 2018

Description

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 27, 2018
Updated Aug 6, 2024
Reserved Nov 23, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 14, 2017