The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-03-01T00:00:00

Updated: 2024-01-30T21:56:51.639818

Reserved: 2018-02-27T00:00:00


Link: CVE-2018-7550

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-03-01T17:29:00.523

Modified: 2024-01-30T22:15:52.420


Link: CVE-2018-7550

JSON object: View

cve-icon Redhat Information

No data.