The pnvlpcdoeccb function in hw/ppc/pnvlpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
{ "urgency": "low" }