Description
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1927-1 | qemu security update |
Debian DSA |
DSA-4506-1 | qemu security update |
Debian DSA |
DSA-4512-1 | qemu security update |
EUVD |
EUVD-2019-4691 | qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass. |
Ubuntu USN |
USN-4191-1 | QEMU vulnerabilities |
Ubuntu USN |
USN-4191-2 | QEMU vulnerabilities |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:41:10.520Z
Reserved: 2019-07-02T00:00:00.000Z
Link: CVE-2019-13164
No data.
Status : Modified
Published: 2019-07-03T14:15:10.370
Modified: 2024-11-21T04:24:20.037
Link: CVE-2019-13164
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN