CVE-2019-8934 PUBLISHED

hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.

EPSS 0.10% · 28.1th percentile

Risk Scores

EPSS Score
0.10%
28.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSqemu0, 1:2.11+dfsg-1ubuntu7.42+esm2, 1:2.11+dfsg-1ubuntu7.42+esm1
Ubuntu:Pro:16.04:LTSqemu1:2.5+dfsg-5ubuntu10.32, 0, 1:2.3+dfsg-5ubuntu9
Ubuntu:Pro:14.04:LTSqemu2.0.0~rc1+dfsg-0ubuntu2, 2.0.0~rc1+dfsg-0ubuntu1, 1.7.0+dfsg-3ubuntu7

Timeline

References

Open in Interactive Console →