qemu: Out-of-bounds read in hw/i2c/i2c-ddc.c allows for memory disclosure
Published Feb 19, 2019
5.5
MEDIUMCVSS 3.0
EPSS 0.43%
Description
QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could exploit this to read stack memory of the qemu process on the host.
Affected products
-
- Version through version 2.10 and through to 3.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The QEMU Project | QEMU | n/a |
|
Configuration 2
- 29
- 30
Configuration 3
- 18.04
- 18.10
No data.
Red Hat Enterprise Linux 5
kvm
Not affected
Red Hat Enterprise Linux 5
xen
Not affected
Red Hat Enterprise Linux 6
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm-rhev
Not affected
Red Hat Enterprise Linux 8
qemu-kvm
Not affected
Red Hat OpenStack Platform 10 (Newton)
qemu-kvm-rhev
Not affected
Red Hat OpenStack Platform 13 (Queens)
qemu-kvm-rhev
Not affected
Red Hat OpenStack Platform 14 (Rocky)
qemu-kvm-rhev
Not affected
Red Hat OpenStack Platform 8 (Liberty)
qemu-kvm-rhev
Not affected
Red Hat OpenStack Platform 9 (Mitaka)
qemu-kvm-rhev
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kvm | Not affected | n/a |
| Red Hat Enterprise Linux 5 | xen | Not affected | n/a |
| Red Hat Enterprise Linux 6 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-rhev | Not affected | n/a |
| Red Hat Enterprise Linux 8 | qemu-kvm | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | qemu-kvm-rhev | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | qemu-kvm-rhev | Not affected | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | qemu-kvm-rhev | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | qemu-kvm-rhev | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | qemu-kvm-rhev | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00094.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00040.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/107059 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-3812 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1665792 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3812 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CGCFIFSIWUREEQQOZDZFBYKWZHXCWBZN/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJMTVGDLA654HNCDGLCUEIP36SNJEKK7/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-3812
- https://seclists.org/bugtraq/2019/May/76 mailing-listx_refsource_BUGTRAQ
- https://usn.ubuntu.com/3923-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3812
- https://www.debian.org/security/2019/dsa-4454 vendor-advisoryx_refsource_DEBIAN
Change history (0)
No recorded changes yet.