The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client could use this flaw to keep the NBD server from serving other requests, resulting in DoS.
CVSS Details
- CVSS 3.1 Base Score: 5.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | May 31, 2018 | Feb 20, 2018 |
| Oracle_linux | — | Upgrade qemu-system-x86Upgrade qemuUpgrade qemu-commonUpgrade qemu-imgUpgrade qemu-block-glusterUpgrade ivshmem-toolsUpgrade qemu-system-aarch64Upgrade qemu-kvmUpgrade qemu-block-iscsiUpgrade qemu-kvm-coreUpgrade qemu-system-x86-coreUpgrade qemu-system-aarch64-coreUpgrade qemu-block-rbd | May 15, 2019 | Nov 28, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 27, 2018 |
| Suse | — | Upgrade qemu-ui-spice-appUpgrade qemuUpgrade qemu-toolsUpgrade qemu-armUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-hw-display-qxlUpgrade qemu-audio-paUpgrade qemu-block-sshUpgrade qemu-ipxeUpgrade qemu-audio-ossUpgrade qemu-ui-cursesUpgrade qemu-skibootUpgrade qemu-ui-openglUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-chardev-spiceUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-ppcUpgrade qemu-sgabiosUpgrade qemu-guest-agentUpgrade qemu-ui-spice-coreUpgrade qemu-seabiosUpgrade qemu-audio-alsaUpgrade qemu-block-curlUpgrade qemu-ksmUpgrade qemu-kvmUpgrade qemu-vgabiosUpgrade qemu-chardev-baumUpgrade qemu-microvmUpgrade qemu-hw-usb-redirectUpgrade qemu-s390xUpgrade qemu-audio-spiceUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-ui-gtkUpgrade qemu-x86Upgrade qemu-s390Upgrade qemu-block-iscsiUpgrade qemu-langUpgrade qemu-block-rbd | Mar 22, 2018 | Feb 20, 2018 |
| Ubuntu | — | Upgrade qemu-systemUpgrade qemu-system-s390xUpgrade qemu-system-miscUpgrade qemu-system-mipsUpgrade qemu-system-ppcUpgrade qemu-system-armUpgrade qemu-system-sparcUpgrade qemu-system-aarch64Upgrade qemu-system-x86 | Feb 21, 2018 | Feb 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub