{"schema_version":"1.7.5","id":"CVE-2018-18438","published":"2018-10-19T22:29:02.287Z","modified":"2026-07-08T05:52:23.652200902Z","related":["CGA-3m3q-fmhw-rjm8","SUSE-SU-2018:3975-1","SUSE-SU-2018:3987-1","SUSE-SU-2019:0825-1","SUSE-SU-2019:0827-1","SUSE-SU-2019:13921-1","SUSE-SU-2019:14011-1"],"details":"Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qemu/qemu","events":[{"introduced":"609d7596524ab204ccd71ef42c9eee4c7c338ea4"},{"last_affected":"823a3f11fb8f04c3c3cc0f95f968fef1bfc6534f"}],"database_specific":{"cpe":["cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.0"},{"last_affected":"6.0"},{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING"}}],"versions":["6.0","7.0","v7.0.0","v7.0.0-rc4","v7.0.0-rc3","v7.0.0-rc2","v7.0.0-rc1","v7.0.0-rc0","v6.2.0","v6.2.0-rc4","v6.1.0","v6.2.0-rc3","v6.2.0-rc1","v6.2.0-rc0","v6.0.0","v6.1.0-rc4","v6.1.0-rc3","v6.1.0-rc2","v6.1.0-rc1","v6.1.0-rc0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-18438.json"}}],"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2018/10/17/3"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/105953"},{"type":"FIX","url":"https://lists.gnu.org/archive/html/qemu-devel/2018-10/msg02396.html"},{"type":"FIX","url":"https://lists.gnu.org/archive/html/qemu-devel/2018-10/msg02402.html"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8"},{"last_affected":"8"},{"introduced":"9"},{"last_affected":"9"},{"introduced":"10"},{"last_affected":"10"},{"introduced":"12"},{"last_affected":"12"},{"introduced":"13"},{"last_affected":"13"}],"source":"CPE_STRING","vendor_product":"redhat:openstack"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}