CVE-2019-13164 PUBLISHED

qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.

EPSS 0.02% · 5.5th percentile

Risk Scores

EPSS Score
0.02%
5.5th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSqemu1:2.11+dfsg-1ubuntu7.19, 1:2.11+dfsg-1ubuntu7.18, 1:2.11+dfsg-1ubuntu7.17
Ubuntu:Pro:14.04:LTSqemu2.0.0+dfsg-2ubuntu1, 2.0.0+dfsg-2ubuntu1.1, 2.0.0+dfsg-2ubuntu1.2
Ubuntu:16.04:LTSqemu1:2.5+dfsg-5ubuntu10.11, 1:2.5+dfsg-5ubuntu10.13, 1:2.5+dfsg-5ubuntu10.14

Timeline

References

Open in Interactive Console →