PT-2017-3734 · Qemu+1 · Qemu+2

Published

2017-07-21

·

Updated

2023-02-12

·

CVE-2017-7539

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Qemu versions prior to 2.10.1 Qemu-NBD (affected versions not specified)
Description: The issue is related to errors during connection establishment in the Qemu-NBD hardware emulator server. It can be exploited by a remote attacker to cause a denial of service by crashing the server when it attempts to respond to a client. The problem arises from an assertion-failure flaw in the NBD server's initial connection negotiation, where the I/O coroutine is undefined, allowing a remote user or process to crash the qemu-nbd server by sending unexpected data during connection negotiation.
Recommendations: For Qemu versions prior to 2.10.1, update to version 2.10.1 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for Qemu-NBD.

Fix

DoS

RCE

Assertion Failure

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1993
ALT-PU-2017-2421
BDU:2019-00222
CVE-2017-7539
RHSA-2017:2628
RHSA-2017:3466
RHSA-2017:3470
RHSA-2017:3471
RHSA-2017:3472
RHSA-2017:3473
RHSA-2017:3474

Affected Products

Alt Linux
Qemu
Qemu-Nbd