CVE-2018-20216

NameCVE-2018-20216
DescriptionQEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qemu (PTS)jessie1:2.1+dfsg-12+deb8u6fixed
jessie (security)1:2.1+dfsg-12+deb8u11fixed
stretch1:2.8+dfsg-6+deb9u5fixed
stretch (security)1:2.8+dfsg-6+deb9u7fixed
buster1:3.1+dfsg-8~deb10u1vulnerable
sid1:3.1+dfsg-8vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
qemusource(unstable)(unfixed)unimportant
qemusourcejessie(not affected)
qemusourcestretch(not affected)
qemu-kvmsource(unstable)(unfixed)medium

Notes

[stretch] - qemu <not-affected> (Vulnerable code not present)
[jessie] - qemu <not-affected> (Vulnerable code not present)
https://lists.gnu.org/archive/html/qemu-devel/2018-12/msg03052.html
https://git.qemu.org/?p=qemu.git;a=commit;h=f1e2e38ee0136b7710a2caa347049818afd57a1b
PVRDMA support not enabled in the binary packages until 1:3.1+dfsg-3, disabled again in 1:3.1+dfsg-4

Search for package or bug name: Reporting problems