Lucene search

K
redhatcveRedhat.comRH:CVE-2018-20815
HistoryOct 10, 2019 - 5:41 a.m.

CVE-2018-20815

2019-10-1005:41:46
redhat.com
access.redhat.com
15

0.011 Low

EPSS

Percentile

84.3%

A heap buffer overflow issue was found in the load_device_tree() function of QEMU, which is invoked to load a device tree blob at boot time. It occurs due to device tree size manipulation before buffer allocation, which could overflow a signed int type. A user/process could use this flaw to potentially execute arbitrary code on a host system with privileges of the QEMU process.