hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings.
https://usn.ubuntu.com/3923-1/
https://lists.gnu.org/archive/html/qemu-devel/2018-12/msg02823.html