PT-2017-4109 · Qemu+1 · Qemu+1

Jann Horn

·

Published

2017-02-10

·

Updated

2024-08-05

·

CVE-2017-8284

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.9.0
Description The issue is related to the disas insn function in target/i386/translate.c of the QEMU emulator, which does not limit the instruction size when TCG mode without hardware acceleration is used. This allows local users to gain privileges by creating a modified basic block that injects code into a setuid program. The vendor has stated that this bug does not violate any security guarantees QEMU makes.
Recommendations For QEMU versions prior to 2.9.0, update to version 2.9.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the disas insn function in target/i386/translate.c until a patch is available. Additionally, avoid using TCG mode without hardware acceleration to minimize the risk of exploitation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1521
BDU:2021-03352
CVE-2017-8284

Affected Products

Alt Linux
Qemu