QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could exploit this to read stack memory of the qemu process on the host.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "18.04"
},
{
"last_affected": "18.10"
}
],
"source": "CPE_FIELD",
"vendor_product": "canonical:ubuntu_linux",
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "29"
},
{
"last_affected": "30"
}
],
"source": "CPE_FIELD",
"vendor_product": "fedoraproject:fedora",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "42.3"
}
],
"source": "CPE_FIELD",
"vendor_product": "opensuse:leap",
"cpes": [
"cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*"
]
}
]
}