PT-2017-18886 · Qemu+3 · Qemu+3

Published

2017-04-25

·

Updated

2020-11-10

·

CVE-2017-9375

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (aka Quick Emulator) versions (affected versions not specified)
Description The issue allows local guest OS privileged users to cause a denial of service, specifically an infinite recursive call. This can be achieved through vectors involving control transfer descriptors sequencing when QEMU is built with USB xHCI controller emulator support.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1521
CVE-2017-9375
DLA-1927-1
DSA-3920-1
DSA-3991-1
OPENSUSE-SU-2017_1872-1
RHSA-2017:2392
RHSA-2017:2408
SUSE-SU-2017:1774-1
SUSE-SU-2017:2946-1
SUSE-SU-2017:2963-1
SUSE-SU-2017:2969-1
SUSE-SU-2017:3084-1
USN-3414-1
USN-3414-2

Affected Products

Alt Linux
Qemu
Suse
Ubuntu