Out-of-bounds read in QEMU - CVE-2017-13672

 

Out-of-bounds read in QEMU - CVE-2017-13672

Published: April 10, 2018


Vulnerability identifier: #VU11644
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13672
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent unauthenticated attacker to cause DoS condition on the target system.

The weakness exists due to out-of-bounds read. An adjacent attacker can trigger memory corruption and cause the service to crash.

Affected software

QEMU
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
SUSE Linux
Fedora
Opensuse
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization
Red Hat OpenStack
Red Hat OpenStack for IBM Power
xen

How to mitigate CVE-2017-13672

Update to version 2.11.1-r1.

xen - addressed in versions 4.7.3-6.fc25, 4.7.3-7.fc25, 4.8.2-3.fc26, 4.8.2-4.fc26, 4.9.0-11.fc27

External References

Related Security Bulletins