Back

MEDIUM

Qemu: Integer overflow in ccid_card_vscard_read() allows memory corruption

Published Oct 19, 2018

Description

Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value.

Affected products

Remediation

Red Hat statement

The maintainer audited the code and determined that no memory corruption is possible using this flaw. Patches were applied upstream to prevent future changes introducing such flaws, but the issues identified by this CVE were determined to not constitute a vulnerability.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 19, 2018
Updated Aug 5, 2024
Reserved Oct 17, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date Oct 11, 2018