Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-12617

48
FAUCET Score

CVE-2018-12617 is an integer overflow vulnerability in the QEMU Guest Agent (qemu-ga) affecting QEMU versions up to 2.12.50, including various Canonical and Debian distributions. This flaw allows an unauthenticated attacker to trigger a denial-of-service (DoS) by sending a specially crafted QMP command with a large count value to the listening socket, causing a segmentation fault due to a failed memory allocation. Rated 7.5 HIGH on the CVSS scale, it presents a network-based attack with low complexity and no user interaction required, leading to high availability impact. While not actively exploited in the wild and not listed on the KEV catalog, public exploit code (EDB-44925) exists, though there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.12.50CPE matchmatch criteria
cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
18.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
18.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
25.35%
Probability of exploitation in next 30 days
EPSS Percentile
97.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-44925 · Jun 22, 2018
This CVE's current EPSS score of 0.2535 is in the 96th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: qemu-kvm
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: virtio-win
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-guest-agent
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: virtio-win

Vendor Advisories (1)

redhatCVE-2018-12617Low

Qemu: qemu-guest-agent: Integer overflow causes segmentation fault in qmp_guest_file_read()

Jun 22, 2018

References

gist.github.com / fakhrizulkifli/c7740d28efa07dafee66d4da5d857ef6
ExploitThird Party Advisory
lists.debian.org / debian-lts-announce/2019/02/msg00041.html
Mailing ListThird Party Advisory
lists.gnu.org / archive/html/qemu-devel/2018-06/msg03385.html
Mailing ListPatchThird Party Advisory
seclists.org / bugtraq/2019/May/76
Mailing ListThird Party Advisory
usn.ubuntu.com / 3826-1
Third Party Advisory
debian.org / security/2019/dsa-4454
Third Party Advisory
exploit-db.com / exploits/44925
ExploitThird Party AdvisoryVDB Entry
securityfocus.com / bid/104531
Third Party AdvisoryVDB Entry