A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker cannot trigger the buffer overflow without first successfully negotiating TLS.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Base Score: 8.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Jul 27, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 27, 2018 |
| Suse | — | Upgrade qemu-hw-display-virtio-vgaUpgrade qemu-ppcUpgrade qemu-toolsUpgrade qemu-s390xUpgrade qemu-sgabiosUpgrade qemu-ipxeUpgrade qemu-audio-paUpgrade qemu-guest-agentUpgrade qemu-x86Upgrade qemu-vgabiosUpgrade qemu-audio-ossUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-armUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemuUpgrade qemu-block-rbdUpgrade qemu-ui-openglUpgrade qemu-hw-display-qxlUpgrade qemu-microvmUpgrade qemu-block-curlUpgrade qemu-ui-spice-coreUpgrade qemu-s390Upgrade qemu-skibootUpgrade qemu-kvmUpgrade qemu-ksmUpgrade qemu-langUpgrade qemu-chardev-spiceUpgrade qemu-seabiosUpgrade qemu-hw-usb-redirectUpgrade qemu-block-iscsiUpgrade qemu-block-sshUpgrade qemu-audio-alsaUpgrade qemu-ui-spice-appUpgrade qemu-audio-spiceUpgrade qemu-chardev-baumUpgrade qemu-ui-gtkUpgrade qemu-ui-curses | May 20, 2018 | Feb 20, 2018 |
| Ubuntu | — | Upgrade qemu-system-sparcUpgrade qemu-system-ppcUpgrade qemu-systemUpgrade qemu-system-mipsUpgrade qemu-system-aarch64Upgrade qemu-system-miscUpgrade qemu-system-x86Upgrade qemu-system-armUpgrade qemu-system-s390x | Feb 21, 2018 | Feb 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub