CVE-2018-19364

NameCVE-2018-19364
Descriptionhw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1646-1, DSA-4454-1
NVD severitylow
Debian Bugs914599

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qemu (PTS)stretch1:2.8+dfsg-6+deb9u9fixed
stretch (security)1:2.8+dfsg-6+deb9u16fixed
buster, buster (security)1:3.1+dfsg-8+deb10u8fixed
bullseye1:5.2+dfsg-11fixed
bullseye (security)1:5.2+dfsg-11+deb11u1fixed
bookworm, sid1:6.1+dfsg-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
qemusourcejessie1:2.1+dfsg-12+deb8u9DLA-1646-1
qemusourcestretch1:2.8+dfsg-6+deb9u6DSA-4454-1
qemusource(unstable)1:3.1+dfsg-1914599
qemu-kvmsource(unstable)(unfixed)

Notes

https://git.qemu.org/?p=qemu.git;a=commit;h=5b76ef50f62079a2389ba28cacaf6cce68b1a0ed
https://git.qemu.org/?p=qemu.git;a=commit;h=5b3c77aa581ebb215125c84b0742119483571e55

Search for package or bug name: Reporting problems