CVE-2018-12617 is an integer overflow vulnerability in the QEMU Guest Agent (qemu-ga) affecting QEMU versions up to 2.12.50, including various Canonical and Debian distributions. This flaw allows an unauthenticated attacker to trigger a denial-of-service (DoS) by sending a specially crafted QMP command with a large count value to the listening socket, causing a segmentation fault due to a failed memory allocation. Rated 7.5 HIGH on the CVSS scale, it presents a network-based attack with low complexity and no user interaction required, leading to high availability impact. While not actively exploited in the wild and not listed on the KEV catalog, public exploit code (EDB-44925) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.12.50CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
18.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.