Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (memory consumption) via a large number of "VIRTIO_GPU_CMD_SET_SCANOUT:" commands.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Jun 1, 2017 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Jun 1, 2017 |
| Ubuntu | — | Upgrade qemu-system-armUpgrade qemu-system-aarch64Upgrade qemu-system-sparcUpgrade qemu-system-x86Upgrade qemu-system-miscUpgrade qemu-systemUpgrade qemu-system-mipsUpgrade qemu-system-s390xUpgrade qemu-system-ppc | Sep 13, 2017 | Jun 1, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub