Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) via vectors involving the order of resource cleanup.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Dec 29, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Dec 29, 2016 |
| Suse | — | Upgrade qemu-audio-paUpgrade qemu-seabiosUpgrade qemu-guest-agentUpgrade qemu-vgabiosUpgrade qemu-kvmUpgrade qemu-ksmUpgrade qemu-ui-gtkUpgrade qemu-s390Upgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-ui-cursesUpgrade qemu-hw-usb-redirectUpgrade qemu-langUpgrade qemu-audio-alsaUpgrade qemu-ui-spice-coreUpgrade qemu-x86Upgrade qemu-chardev-baumUpgrade qemu-block-iscsiUpgrade qemu-s390xUpgrade qemu-ppcUpgrade qemu-microvmUpgrade qemu-block-curlUpgrade qemu-hw-display-qxlUpgrade qemu-toolsUpgrade qemu-sgabiosUpgrade qemu-audio-ossUpgrade qemuUpgrade qemu-block-rbdUpgrade qemu-block-sshUpgrade qemu-ui-openglUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-audio-spiceUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-skibootUpgrade qemu-armUpgrade qemu-ipxeUpgrade qemu-chardev-spiceUpgrade qemu-ui-spice-appUpgrade qemu-hw-display-virtio-gpu-pci | Jan 14, 2017 | Dec 29, 2016 |
| Ubuntu | — | Upgrade qemu-system-miscUpgrade qemu-system-armUpgrade qemu-system-aarch64Upgrade qemu-system-sparcUpgrade qemu-system-x86Upgrade qemu-system-s390xUpgrade qemu-systemUpgrade qemu-system-ppcUpgrade qemu-system-mips | Apr 21, 2017 | Dec 29, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub