Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) via vectors involving the order of resource cleanup.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Dec 29, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Dec 29, 2016 |
| Suse | — | Upgrade qemu-ksmUpgrade qemu-guest-agentUpgrade qemu-ui-spice-coreUpgrade qemu-block-curlUpgrade qemu-seabiosUpgrade qemu-ppcUpgrade qemu-s390Upgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-ui-cursesUpgrade qemu-audio-paUpgrade qemu-hw-usb-redirectUpgrade qemu-x86Upgrade qemu-microvmUpgrade qemu-chardev-baumUpgrade qemu-ui-gtkUpgrade qemu-s390xUpgrade qemu-audio-alsaUpgrade qemu-kvmUpgrade qemu-block-iscsiUpgrade qemu-vgabiosUpgrade qemu-langUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-skibootUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-audio-ossUpgrade qemu-block-rbdUpgrade qemu-ui-spice-appUpgrade qemu-ui-openglUpgrade qemu-block-sshUpgrade qemu-audio-spiceUpgrade qemu-toolsUpgrade qemu-sgabiosUpgrade qemu-hw-display-virtio-vgaUpgrade qemuUpgrade qemu-chardev-spiceUpgrade qemu-ipxeUpgrade qemu-hw-display-qxlUpgrade qemu-arm | Jan 14, 2017 | Dec 29, 2016 |
| Ubuntu | — | Upgrade qemu-system-aarch64Upgrade qemu-system-sparcUpgrade qemu-system-x86Upgrade qemu-system-miscUpgrade qemu-system-armUpgrade qemu-system-s390xUpgrade qemu-system-ppcUpgrade qemu-systemUpgrade qemu-system-mips | Apr 21, 2017 | Dec 29, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub