Vulnerability Name:

CVE-2018-20191 (CCN-154399)

Assigned:2018-12-18
Published:2018-12-18
Updated:2020-05-12
Summary:hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference).
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-476
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-20191

Source: MLIST
Type: Mailing List, Patch, Third Party Advisory
[oss-security] 20181218 CVE-2018-20191 QEMU: pvrdma: uar_read leads to NULL dereference

Source: BID
Type: Third Party Advisory, VDB Entry
106276

Source: XF
Type: UNKNOWN
qemu-cve201820191-dos(154399)

Source: FEDORA
Type: Broken Link
FEDORA-2019-88a98ce795

Source: FEDORA
Type: Broken Link
FEDORA-2019-0664c7724d

Source: CCN
Type: qemu-devel Web site
Re: [Qemu-devel] [PATCH v2 2/6] pvrdma: add uar_read routine

Source: MLIST
Type: Patch, Third Party Advisory
[qemu-devel] 20181213 Re: [PATCH v2 2/6] pvrdma: add uar_read routine

Source: CCN
Type: oss-sec Mailing List, Tue, 18 Dec 2018 14:20:49 +0530 (IST)
CVE-2018-20191 QEMU: pvrdma: uar_read leads to NULL dereference

Source: UBUNTU
Type: Third Party Advisory
USN-3923-1

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2018-20191

Vulnerable Configuration:Configuration 1:
  • cpe:/a:qemu:qemu:*:*:*:*:*:*:*:* (Version <= 3.1.0)

  • Configuration 2:
  • cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:29:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:30:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:qemu:qemu:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:618
    P
    Security update for python (Important) (in QA)
    2022-10-06
    oval:org.opensuse.security:def:201820191
    V
    CVE-2018-20191
    2022-08-07
    oval:org.opensuse.security:def:555
    P
    Security update for php8 (Important)
    2022-07-06
    oval:org.opensuse.security:def:95148
    P
    qemu-6.2.0-150400.35.10 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:3187
    P
    qemu-tools-6.2.0-150400.35.10 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:3518
    P
    qemu-6.2.0-150400.35.10 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94817
    P
    qemu-tools-6.2.0-150400.35.10 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:296
    P
    qemu-tools-5.2.0-9.18 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:351
    P
    qemu-6.2.0-150400.35.10 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:94238
    P
    (Important)
    2022-05-17
    oval:org.opensuse.security:def:880
    P
    Security update for tar (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:1065
    P
    Security update for firewalld, golang-github-prometheus-prometheus (Important)
    2022-04-27
    oval:org.opensuse.security:def:1652
    P
    Security update for apache2 (Important)
    2022-03-29
    oval:org.opensuse.security:def:1587
    P
    Security update for python-libxml2-python (Important)
    2022-03-10
    oval:org.opensuse.security:def:94239
    P
    (Important)
    2022-01-25
    oval:org.opensuse.security:def:113318
    P
    qemu-6.1.0-32.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:1651
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:69972
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:1225
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:67802
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15) (Important)
    2021-11-17
    oval:org.opensuse.security:def:106728
    P
    qemu-6.1.0-32.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:103722
    P
    qemu-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:97032
    P
    qemu-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71327
    P
    libunwind-1.2.1-2.13 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63232
    P
    qemu-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89799
    P
    qemu-tools-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61644
    P
    qemu-tools-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:2143
    P
    qemu-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71155
    P
    ceph-common-14.2.0.300+gacd2f2b9e1-1.12 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71385
    P
    qemu-tools-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:90067
    P
    qemu-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103454
    P
    qemu-tools-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96764
    P
    qemu-tools-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:66908
    P
    Security update for mariadb (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:66907
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:100649
    P
    (Moderate)
    2021-08-23
    oval:org.opensuse.security:def:48047
    P
    iputils-s20121221-2.17 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47091
    P
    libvdpau1-1.1.1-6.73 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48202
    P
    libsystemd0-228-155.21 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48287
    P
    python-pywbem-0.7.0-4.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47405
    P
    libruby2_1-2_1-2.1.9-18.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47586
    P
    cups-pk-helper-0.2.5-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48304
    P
    screen-4.0.4-23.3.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47629
    P
    gpgme-1.5.1-1.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47601
    P
    ecryptfs-utils-103-8.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47991
    P
    dhcp-4.3.3-10.16.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47915
    P
    vsftpd-3.0.2-40.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47077
    P
    libspice-client-glib-2_0-8-0.31-7.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48137
    P
    libkde4-32bit-4.12.0-10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48139
    P
    libksba8-1.3.0-23.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47212
    P
    automake-1.13.4-6.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48233
    P
    libzip2-0.11.1-13.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47537
    P
    xorg-x11-server-7.6_1.18.3-71.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47587
    P
    curl-7.60.0-2.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47777
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47722
    P
    libipa_hbac0-1.16.1-2.8 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47076
    P
    libsoup-2_4-1-2.54.1-4.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48075
    P
    libXext6-1.3.2-4.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:64740
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:63368
    P
    qemu-5.2.0-9.18 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2279
    P
    qemu-5.2.0-9.18 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:101394
    P
    qemu-5.2.0-9.18 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:72055
    P
    qemu-tools-5.2.0-9.18 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101072
    P
    qemu-tools-5.2.0-9.18 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100951
    P
    libpango-1_0-0-1.44.7+11-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100952
    P
    libpcap-devel-1.9.1-1.33 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62314
    P
    qemu-tools-5.2.0-9.18 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:70263
    P
    Security update for linuxptp (Important)
    2021-07-27
    oval:org.opensuse.security:def:70264
    P
    Security update for MozillaFirefox (Important)
    2021-07-27
    oval:org.opensuse.security:def:69867
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:48585
    P
    openvswitch-2.5.1-24.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48942
    P
    libpolkit0-32bit-0.113-5.12.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48712
    P
    bogofilter-1.2.4-3.56 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48814
    P
    python-devel-2.7.9-24.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:66815
    P
    Security update for the Linux Kernel (Important)
    2021-06-08
    oval:org.opensuse.security:def:48501
    P
    libhivex0-1.3.10-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71042
    P
    libvpx4-1.6.1-4.16 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48647
    P
    wpa_supplicant-2.2-14.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:66816
    P
    Security update for qemu (Important)
    2021-06-08
    oval:org.opensuse.security:def:48743
    P
    libraw9-0.15.4-3.88 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:67987
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) (Important)
    2021-05-25
    oval:org.opensuse.security:def:73598
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:73599
    P
    Security update for ruby2.5 (Moderate)
    2021-04-20
    oval:org.opensuse.security:def:64455
    P
    Security update for curl (Moderate)
    2021-04-01
    oval:org.opensuse.security:def:64653
    P
    Security update for postgresql12 (Moderate)
    2021-02-22
    oval:org.opensuse.security:def:68087
    P
    Security update for the Linux Kernel (Live Patch 14 for SLE 15 SP1) (Important)
    2021-02-10
    oval:org.opensuse.security:def:93936
    P
    (Moderate)
    2020-12-10
    oval:org.opensuse.security:def:107315
    P
    qemu-tools-4.2.0-9.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63296
    P
    qemu-4.2.0-9.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107617
    P
    qemu-4.2.0-9.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61969
    P
    qemu-tools-4.2.0-9.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2207
    P
    qemu-4.2.0-9.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63297
    P
    qemu-audio-oss-3.1.1.1-9.21.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71440
    P
    autofs-5.1.3-7.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71710
    P
    qemu-tools-4.2.0-9.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107618
    P
    qemu-audio-oss-3.1.1.1-9.21.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48996
    P
    ibus-gtk3-32bit-1.5.13-15.11.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2208
    P
    qemu-audio-oss-3.1.1.1-9.21.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:50093
    P
    qemu-audio-oss on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73307
    P
    qemu-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67702
    P
    libnewt0_52 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50038
    P
    subversion-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49321
    P
    qemu-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70159
    P
    ctags on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66524
    P
    libseccomp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73189
    P
    libnm0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50039
    P
    sysstat-isag on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50028
    P
    qemu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49267
    P
    libykcs11-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73480
    P
    FastCGI on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64368
    P
    libpng12-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50092
    P
    qemu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49974
    P
    rarpd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73481
    P
    ant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66616
    P
    qemu-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70158
    P
    crash on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:201820191000
    V
    CVE-2018-20191 on Ubuntu 18.04 LTS (bionic) - low.
    2018-12-20
    oval:com.ubuntu.cosmic:def:2018201910000000
    V
    CVE-2018-20191 on Ubuntu 18.10 (cosmic) - low.
    2018-12-20
    oval:com.ubuntu.cosmic:def:201820191000
    V
    CVE-2018-20191 on Ubuntu 18.10 (cosmic) - low.
    2018-12-20
    oval:com.ubuntu.bionic:def:2018201910000000
    V
    CVE-2018-20191 on Ubuntu 18.04 LTS (bionic) - low.
    2018-12-20
    oval:com.ubuntu.trusty:def:201820191000
    V
    CVE-2018-20191 on Ubuntu 14.04 LTS (trusty) - low.
    2018-12-20
    oval:com.ubuntu.xenial:def:2018201910000000
    V
    CVE-2018-20191 on Ubuntu 16.04 LTS (xenial) - low.
    2018-12-20
    oval:com.ubuntu.xenial:def:201820191000
    V
    CVE-2018-20191 on Ubuntu 16.04 LTS (xenial) - low.
    2018-12-20
    BACK
    qemu qemu *
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    canonical ubuntu linux 18.04
    canonical ubuntu linux 18.10
    fedoraproject fedora 29
    fedoraproject fedora 30
    qemu qemu -