A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Jul 27, 2018 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Apr 10, 2017 |
| Oracle_linux | — | Upgrade ivshmem-toolsUpgrade qemu-system-x86-coreUpgrade qemu-commonUpgrade qemu-system-aarch64Upgrade qemu-block-rbdUpgrade qemu-block-glusterUpgrade qemuUpgrade qemu-kvm-coreUpgrade qemu-kvmUpgrade qemu-block-iscsiUpgrade qemu-imgUpgrade qemu-system-aarch64-coreUpgrade qemu-system-x86 | Oct 30, 2018 | Feb 3, 2017 |
| Suse | — | Upgrade qemu-audio-paUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-armUpgrade qemu-sgabiosUpgrade qemu-hw-display-virtio-gpuUpgrade qemuUpgrade qemu-guest-agentUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-ppcUpgrade qemu-hw-display-qxlUpgrade qemu-ui-openglUpgrade qemu-langUpgrade qemu-ui-spice-appUpgrade qemu-toolsUpgrade qemu-chardev-spiceUpgrade qemu-skibootUpgrade qemu-audio-ossUpgrade qemu-ui-cursesUpgrade qemu-block-curlUpgrade qemu-ui-gtkUpgrade qemu-ksmUpgrade qemu-ipxeUpgrade qemu-block-sshUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-hw-usb-redirectUpgrade qemu-microvmUpgrade qemu-kvmUpgrade qemu-x86Upgrade qemu-block-rbdUpgrade qemu-seabiosUpgrade qemu-ui-spice-coreUpgrade qemu-audio-alsaUpgrade qemu-audio-spiceUpgrade qemu-block-iscsiUpgrade qemu-s390Upgrade qemu-s390xUpgrade qemu-vgabiosUpgrade qemu-chardev-baum | Jul 21, 2017 | Jul 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub