CVE-2018-12617 EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 25.1% (pctl 98)
Patch early
A public exploit exists.
Description
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be exploited by sending a crafted QMP command (including guest-file-read with a large count value) to the agent via the listening socket.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 25.05% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-190 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-06-21 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| qemu | qemu |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | QEMU Guest Agent 2.12.50 - Denial of Service | 2018-06-22 |
References
- http://www.securityfocus.com/bid/104531
- https://gist.github.com/fakhrizulkifli/c7740d28efa07dafee66d4da5d857ef6
- https://lists.debian.org/debian-lts-announce/2019/02/msg00041.html
- https://lists.gnu.org/archive/html/qemu-devel/2018-06/msg03385.html
- https://seclists.org/bugtraq/2019/May/76
- https://usn.ubuntu.com/3826-1/
- https://www.debian.org/security/2019/dsa-4454
- https://www.exploit-db.com/exploits/44925/
- http://www.securityfocus.com/bid/104531
- https://gist.github.com/fakhrizulkifli/c7740d28efa07dafee66d4da5d857ef6
- https://lists.debian.org/debian-lts-announce/2019/02/msg00041.html
- https://lists.gnu.org/archive/html/qemu-devel/2018-06/msg03385.html
- https://seclists.org/bugtraq/2019/May/76
- https://usn.ubuntu.com/3826-1/
- https://www.debian.org/security/2019/dsa-4454
- https://www.exploit-db.com/exploits/44925/
→ the Explorer · watch your stack · NVD