PT-2017-3861 · Qemu+3 · Qemu+3

Eric Blake

·

Published

2017-11-28

·

Updated

2019-10-09

·

CVE-2017-15119

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.11
Description The issue is related to a denial of service problem in the Network Block Device (NBD) server. It can be triggered by a client sending large option requests, causing the server to waste CPU time. This could allow a remote attacker to keep the NBD server from serving other requests, resulting in a denial of service.
Recommendations For versions prior to 2.11, update to version 2.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the NBD server to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2829
ALT-PU-2018-1076
ALT-PU-2018-2521
BDU:2019-04100
CVE-2017-15119
DSA-4213-1
OPENSUSE-SU-2018_0780-1
RHSA-2018:1104
RHSA-2018:1113
SUSE-SU-2018:0762-1
SUSE-SU-2018:0831-1
USN-3575-1
USN-3575-2

Affected Products

Alt Linux
Qemu
Suse
Ubuntu