hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Mar 21, 2019 |
| Oracle_linux | — | Upgrade ivshmem-toolsUpgrade qemu-imgUpgrade qemu-system-aarch64-coreUpgrade qemu-system-aarch64Upgrade qemu-block-glusterUpgrade qemu-block-iscsiUpgrade qemu-kvmUpgrade qemu-kvm-coreUpgrade qemuUpgrade qemu-block-rbdUpgrade qemu-common | May 15, 2019 | Feb 2, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 21, 2019 |
| Suse | — | Upgrade qemu-ppcUpgrade qemu-ipxeUpgrade qemu-ui-spice-appUpgrade qemuUpgrade qemu-block-glusterUpgrade qemu-block-sshUpgrade qemu-toolsUpgrade qemu-ui-openglUpgrade qemu-guest-agentUpgrade qemu-skibootUpgrade qemu-chardev-spiceUpgrade qemu-block-dmgUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-langUpgrade qemu-audio-paUpgrade qemu-ui-cursesUpgrade qemu-hw-display-qxlUpgrade qemu-armUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-audio-ossUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-block-iscsiUpgrade qemu-seabiosUpgrade qemu-ui-gtkUpgrade qemu-block-rbdUpgrade qemu-s390Upgrade qemu-x86Upgrade qemu-block-curlUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-audio-spiceUpgrade qemu-extraUpgrade qemu-s390xUpgrade qemu-ksmUpgrade qemu-ui-spice-coreUpgrade qemu-microvmUpgrade qemu-kvmUpgrade qemu-hw-usb-redirectUpgrade qemu-chardev-baumUpgrade qemu-sgabiosUpgrade qemu-vgabiosUpgrade qemu-audio-alsa | Apr 17, 2019 | Mar 21, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub