CVE-2018-18954: Canonical Ubuntu Linux
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 18.10 only
- Opensuse Leap: version 42.3 only
- Qemu Qemu: before 3.1 (fixed in 3.1)
Published 2018-11-15. Last modified 2026-06-17.