qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-07-03T13:56:52
Updated: 2021-01-04T18:14:20
Reserved: 2019-07-02T00:00:00
Link: CVE-2019-13164
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-07-03T14:15:10.370
Modified: 2022-10-06T19:51:02.317
Link: CVE-2019-13164
JSON object: View
Redhat Information
No data.
CWE