CVE-2019-6778

Related Vulnerabilities: CVE-2019-6778  

Impact: Important Public Date: 2019-01-11 CWE: CWE-122 Bugzilla: 1664205: CVE-2019-6778 QEMU: slirp: heap buffer overflow in tcp_emu() A heap buffer overflow issue was found in the SLiRP networking implementation of the QEMU emulator. It occurs in tcp_emu() routine while emulating the Identification protocol and copying message data to a socket buffer. A user or process could use this flaw to crash the QEMU process on the host resulting in a DoS or potentially executing arbitrary code with privileges of the QEMU process.

A heap buffer overflow issue was found in the SLiRP networking implementation of the QEMU emulator. It occurs in tcp_emu() routine while emulating the Identification protocol and copying message data to a socket buffer. A user or process could use this flaw to crash the QEMU process on the host resulting in a DoS or potentially executing arbitrary code with privileges of the QEMU process.

Find out more about CVE-2019-6778 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat OpenStack Platform:
This flaw impacts KVM user-mode or SLIRP networking, which is not used in Red Hat OpenStack. Updating is recommended, however Red Hat OpenStack installs are not vulnerable to the described flaw due to the vulnerable feature not being used.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.8
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Changed
Confidentiality High
Integrity Impact High
Availability Impact High

Affected Packages State

Platform Package State
Red Hat OpenStack Platform 9.0 qemu-kvm-rhev Affected
Red Hat OpenStack Platform 8.0 (Liberty) qemu-kvm-rhev Affected
Red Hat OpenStack Platform 14 qemu-kvm-rhev Affected
Red Hat OpenStack Platform 13.0 (Queens) qemu-kvm-rhev Affected
Red Hat OpenStack Platform 10 qemu-kvm-rhev Affected
Red Hat Enterprise Linux 7 qemu-kvm-rhev Affected
Red Hat Enterprise Linux 7 qemu-kvm Affected
Red Hat Enterprise Linux 6 qemu-kvm Affected
Red Hat Enterprise Linux 5 kvm Fix deferred
Red Hat Enterprise Linux 5 xen Not affected

Acknowledgements

Red Hat would like to thank Kira (Tencent Keen Security Lab) for reporting this issue.