PT-2018-7148 · Qemu+1 · Qemu+1

Vladimir Sementsov-Ogievskiy

·

Published

2017-04-25

·

Updated

2024-06-15

·

CVE-2017-2630

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: QEMU versions prior to 2.9
Description: A stack buffer overflow issue was found in QEMU when built with NBD client support. This issue could occur while processing a server's response to a 'NBD OPT LIST' request. A malicious NBD server could potentially use this issue to crash a remote NBD client, resulting in a denial of service, or execute arbitrary code on the client host with the privileges of the QEMU process.
Recommendations: For QEMU versions prior to 2.9, update to version 2.9 or later to resolve the issue. As a temporary workaround, consider disabling the NBD client support until a patch is available. Restrict access to untrusted NBD servers to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1521
CVE-2017-2630
OPENSUSE-SU-2024:11287-1
RHSA-2017:2392

Affected Products

Alt Linux
Qemu