A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker cannot trigger the buffer overflow without first successfully negotiating TLS.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Base Score: 8.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Jul 27, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 27, 2018 |
| Suse | — | Upgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-ui-openglUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-hw-display-qxlUpgrade qemu-sgabiosUpgrade qemu-audio-paUpgrade qemu-ppcUpgrade qemu-toolsUpgrade qemu-hw-display-virtio-vgaUpgrade qemuUpgrade qemu-s390xUpgrade qemu-ipxeUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-vgabiosUpgrade qemu-armUpgrade qemu-block-rbdUpgrade qemu-x86Upgrade qemu-audio-ossUpgrade qemu-guest-agentUpgrade qemu-ui-cursesUpgrade qemu-langUpgrade qemu-seabiosUpgrade qemu-chardev-baumUpgrade qemu-hw-usb-redirectUpgrade qemu-microvmUpgrade qemu-ksmUpgrade qemu-kvmUpgrade qemu-s390Upgrade qemu-ui-gtkUpgrade qemu-ui-spice-appUpgrade qemu-audio-spiceUpgrade qemu-ui-spice-coreUpgrade qemu-block-iscsiUpgrade qemu-block-curlUpgrade qemu-skibootUpgrade qemu-audio-alsaUpgrade qemu-chardev-spiceUpgrade qemu-block-ssh | May 20, 2018 | Feb 20, 2018 |
| Ubuntu | — | Upgrade qemu-systemUpgrade qemu-system-miscUpgrade qemu-system-aarch64Upgrade qemu-system-mipsUpgrade qemu-system-sparcUpgrade qemu-system-ppcUpgrade qemu-system-armUpgrade qemu-system-x86Upgrade qemu-system-s390x | Feb 21, 2018 | Feb 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub