Rapid7

vulnerability

Amazon Linux AMI 2: CVE-2018-7858: Security patch for qemu-kvm (Multiple Advisories)

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:N/I:N/A:P)
Published
Mar 12, 2018
Added
Apr 27, 2020
Modified
May 20, 2026

Description

Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.

Solutions

amazon-linux-ami-2-upgrade-qemu-imgamazon-linux-ami-2-upgrade-qemu-kvmamazon-linux-ami-2-upgrade-qemu-kvm-commonamazon-linux-ami-2-upgrade-qemu-kvm-debuginfoamazon-linux-ami-2-upgrade-qemu-kvm-tools
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.