PT-2017-4109 · Qemu+1 · Qemu+1

Jann Horn

·

Publicado

2017-02-10

·

Atualizado

2024-08-05

·

CVE-2017-8284

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.9.0
Description The issue is related to the disas insn function in target/i386/translate.c of the QEMU emulator, which does not limit the instruction size when TCG mode without hardware acceleration is used. This allows local users to gain privileges by creating a modified basic block that injects code into a setuid program. The vendor has stated that this bug does not violate any security guarantees QEMU makes.
Recommendations For QEMU versions prior to 2.9.0, update to version 2.9.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the disas insn function in target/i386/translate.c until a patch is available. Additionally, avoid using TCG mode without hardware acceleration to minimize the risk of exploitation.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1521
BDU:2021-03352
CVE-2017-8284

Produtos afetados

Alt Linux
Qemu