A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker cannot trigger the buffer overflow without first successfully negotiating TLS.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Base Score: 8.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Jul 27, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 27, 2018 |
| Suse | — | Upgrade qemu-sgabiosUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-hw-display-qxlUpgrade qemu-x86Upgrade qemu-hw-display-virtio-gpuUpgrade qemu-toolsUpgrade qemu-audio-paUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-ui-openglUpgrade qemu-ppcUpgrade qemu-block-rbdUpgrade qemu-ipxeUpgrade qemu-s390xUpgrade qemu-guest-agentUpgrade qemu-vgabiosUpgrade qemu-audio-ossUpgrade qemuUpgrade qemu-armUpgrade qemu-kvmUpgrade qemu-block-sshUpgrade qemu-ui-spice-coreUpgrade qemu-audio-alsaUpgrade qemu-chardev-spiceUpgrade qemu-chardev-baumUpgrade qemu-audio-spiceUpgrade qemu-ui-spice-appUpgrade qemu-ui-gtkUpgrade qemu-seabiosUpgrade qemu-ksmUpgrade qemu-ui-cursesUpgrade qemu-microvmUpgrade qemu-skibootUpgrade qemu-s390Upgrade qemu-block-iscsiUpgrade qemu-hw-usb-redirectUpgrade qemu-block-curlUpgrade qemu-lang | May 20, 2018 | Feb 20, 2018 |
| Ubuntu | — | Upgrade qemu-system-ppcUpgrade qemu-systemUpgrade qemu-system-sparcUpgrade qemu-system-miscUpgrade qemu-system-mipsUpgrade qemu-system-aarch64Upgrade qemu-system-armUpgrade qemu-system-x86Upgrade qemu-system-s390x | Feb 21, 2018 | Feb 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub