In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
https://security.netapp.com/advisory/ntap-20190411-0006/
https://lists.gnu.org/archive/html/qemu-devel/2019-01/msg02324.html
https://access.redhat.com/errata/RHSA-2019:2553
https://access.redhat.com/errata/RHSA-2019:2425