Out-of-bounds write in QEMU - CVE-2017-15289
Published: April 12, 2018
Vulnerability identifier: #VU11790
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15289
CWE-ID: CWE-787
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an adjacent authenticated attacker to cause DoS condition on the target system.
The weakness exists in the mode4and5 write functions in hw/display/cirrus_vga.c due to out-of-bounds write. An adjacent attacker can trigger memory corruption and cause the service to crash via vectors related to dst calculation.
The weakness exists in the mode4and5 write functions in hw/display/cirrus_vga.c due to out-of-bounds write. An adjacent attacker can trigger memory corruption and cause the service to crash via vectors related to dst calculation.
Affected software
QEMU
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Oracle VM Server for x86
Red Hat OpenStack
Red Hat Virtualization
qemu-kvm-rhev (Red Hat package)
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Oracle VM Server for x86
Red Hat OpenStack
Red Hat Virtualization
qemu-kvm-rhev (Red Hat package)
How to mitigate CVE-2017-15289
Install update from vendor's website.
qemu-kvm-rhev (Red Hat package) - update to 2.9.0-16.el7_4.11
External References
Related Security Bulletins
- SUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- OpenSUSE Linux update for xen
- OpenSUSE Linux update for xen
- SUSE Linux update for xen
- Amazon Linux AMI update for qemu-kvm
- Debian update for qemu
- Red Hat update for qemu-kvm
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm-rhev
- Red Hat update for qemu-kvm
- Multiple vulnerabilities in Oracle VM Server
- Red Hat Enterprise Linux OpenStack Platform 6 update for qemu-kvm-rhev