
oss-sec mailing list archives
CVE-2018-20815 QEMU: device_tree: heap buffer overflow while loading device tree blob
From: P J P <ppandit () redhat com>
Date: Wed, 27 Mar 2019 15:35:59 +0530 (IST)
Hello,A heap buffer overflow issue was found in the load_device_tree() function of QEMU, which is invoked to load device tree blob at boot time. It occurs due to device tree size manipulation before buffer allocation, which could overflow a signed int type.
A user/process could use this flaw to potentially execute arbitrary code on a host system with privileges of the QEMU process.
Upstream patch: --------------- -> https://git.qemu.org/?p=qemu.git;a=commitdiff;h=da885fe1ee8b4589047484bd7fa05a4905b52b17 'CVE-2018-20815' assigned via -> https://cveform.mitre.org/ Thank you. -- Prasad J Pandit / Red Hat Product Security Team 47AF CE69 3A90 54AA 9045 1053 DD13 3D32 FE5B 041F
Current thread:
- CVE-2018-20815 QEMU: device_tree: heap buffer overflow while loading device tree blob P J P (Mar 27)