3.3
CVSSv3

CVE-2019-8934

Published: 21/03/2019 Updated: 05/04/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

hw/ppc/spapr.c in QEMU up to and including 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

opensuse leap 15.0

opensuse leap 42.3

Vendor Advisories

Debian Bug report logs - #922923 qemu: CVE-2019-8934: ppc64: sPAPR emulator leaks the host hardware identity Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 21 Feb 2019 21:27:02 UTC Severity: norm ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2019-8934 QEMU: ppc64: sPAPR emulator leaks the host hardware identity <!--X-Subject-Header-End--> <!--X-Head-of-Message-- ...